目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-100658— Netty 4.1.138 之前 WebSocket 拒绝服务漏洞

一分钟漏洞结论

影响对象
netty netty
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Netty(io.netty:netty-codec-http)中的 WebSocketServerExtensionHandler 存在一个未限制大小的每连接队列。该处理器会为每个传入的 HttpRequest 向每通道的 validExtensions 队列提供入口,但仅在应用程序写入 HttpResponse 时才从队列中取出条目,且队列大小从未进行限制。远程未认证的peer可以通过HTTP/1.1管道化技术,以比应用程序生成响应更快的速度发送请求(包括发往任意路径的普通非升级HTTP请求),导致队列无限增长

CVSS 5.3 · Medium EPSS 0.35% · P26
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-100658 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler
来源: CVE Program / CVE List V5
Vulnerability Description
Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue in WebSocketServerExtensionHandler. The handler offers an entry to its per-channel validExtensions queue for every inbound HttpRequest, but polls an entry only when the application writes an HttpResponse, and the queue size is never bounded. A remote, unauthenticated peer can use HTTP/1.1 pipelining to send requests faster than the application produces responses — including plain non-upgrade HTTP requests to any path — causing the queue to grow without limit until the JVM exhausts heap memory and terminates with OutOfMemoryError. Because the affected handler is the base class of WebSocketServerCompressionHandler, any server that enables permessage-deflate is exposed on its plain HTTP port before any WebSocket upgrade completes and before any application-level authentication. Affected versions are 4.1.88.Final through 4.1.137.Final and 4.2.0.Final through 4.2.17.Final; the issue is fixed in 4.1.138.Final and 4.2.18.Final.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
netty netty 4.1.88.Final ~ 4.1.138.Final -
netty netty 4.2.0.Final ~ 4.2.18.Final -

二、漏洞 CVE-2026-100658 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-100658 的情报信息

请登录查看更多情报信息。

CVE-2026-100658 厂商安全公告 (1)

CVE-2026-100658 其他参考 (1)

同批安全公告 · netty · 2026-09-26 · 共 12 条

CVE-2026-100655 7.5 HIGH Netty 4.1.138之前版本 SpdySessionHandler拒绝服务漏洞
CVE-2026-100663 7.5 HIGH Netty HTTP/1 CONNECT 授权形式错误转换导致 HTTP/3 畸形漏洞
CVE-2026-100656 7.5 HIGH Netty HttpServerCodec HTTP/1.1流水线队列无限增长漏洞
CVE-2026-100661 7.5 HIGH Netty HTTP/3 QPACK 前缀整数拒绝服务漏洞
CVE-2026-100660 7.5 HIGH Netty 4.2.18 之前版本 QpackEncoder 无限内存保留漏洞
CVE-2026-100665 7.5 HIGH Netty 4.2.11至4.2.17 QUIC主机名验证绕过漏洞
CVE-2026-100662 7.5 HIGH Netty HTTP/3 QPACK 编码器流无限内存耗尽拒绝服务漏洞
CVE-2026-100664 7.5 HIGH Netty 4.2.2-4.2.17 HTTP/1 主机头授权混淆漏洞
CVE-2026-100657 7.5 HIGH Netty 4.1.138之前版本 StompSubframeDecoder字节缓冲区泄漏漏洞
CVE-2026-100666 7.3 HIGH Netty 4.2.0到4.2.16 通过HttpServerCodec的响应不同步漏洞
CVE-2026-100659 6.5 MEDIUM Netty 4.2.0-4.2.17 HTTP/3 请求路由绕过漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-100658

暂无评论


发表评论