Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100657— Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder

Quick assessment

Affected
netty netty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Netty 的 STOMP 编解码器(io.netty:netty-codec-stomp)在 StompSubframeDecoder 中存在 ByteBuf 内存泄漏问题。当帧声明的 content-length 被完全读取后,解码器会从通道分配器(channel allocator)分配一个缓冲区(chunk buffer),并将其暂存在实例字段中,等待终止该帧的单个 NUL 字节。如果该 NUL 字节始终未到达,缓冲区将永远不会被释放:由于 skipNullCharacter 方法抛出的 replay Si

CVSS 7.5 · High EPSS 0.34% · P25

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100657

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder
Source: CVE Program / CVE List V5
Vulnerability Description
Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared content-length has been fully read, the decoder allocates a chunk buffer from the channel allocator and parks it in an instance field while waiting for the single NUL byte that terminates the frame. If that byte never arrives, the buffer is never released: the replay Signal thrown by skipNullCharacter extends Error rather than Exception, so the decoder's catch(Exception) release path does not run, and StompSubframeDecoder overrides neither handlerRemoved0 nor channelInactive, so the buffer also survives channel teardown. A remote peer can leak one allocator buffer per connection by sending a complete, well-formed frame body and withholding its terminating NUL byte; with the default pooled allocator the memory is never returned to the pool or reclaimed by garbage collection, so the leak accumulates for the lifetime of the process and can lead to memory exhaustion. This affects versions up to and including 4.1.137.Final and versions 4.2.0.Final through 4.2.17.Final; it is fixed in 4.1.138.Final and 4.2.18.Final.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对已超过有效生命周期的资源丧失索引
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
netty netty 0 ~ 4.1.138.Final -
netty netty 4.2.0.Final ~ 4.2.18.Final -

II. Public POCs for CVE-2026-100657

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100657

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100657 (1)

Other References for CVE-2026-100657 (1)

Same Patch Batch · netty · 2026-09-26 · 12 CVEs total

CVE-2026-100655 7.5 HIGH Netty before 4.1.138.Final Denial of Service via SpdySessionHandler
CVE-2026-100663 7.5 HIGH Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3
CVE-2026-100656 7.5 HIGH Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining
CVE-2026-100661 7.5 HIGH Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation
CVE-2026-100660 7.5 HIGH Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention
CVE-2026-100665 7.5 HIGH Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass
CVE-2026-100662 7.5 HIGH Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS
CVE-2026-100664 7.5 HIGH Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion
CVE-2026-100666 7.3 HIGH Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec
CVE-2026-100659 6.5 MEDIUM Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass
CVE-2026-100658 5.3 MEDIUM Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler

IV. Related Vulnerabilities

V. Comments for CVE-2026-100657

No comments yet


Leave a comment