Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100658— Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler

Quick assessment

Affected
netty netty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Netty(io.netty:netty-codec-http)中的 WebSocketServerExtensionHandler 存在一个未限制大小的每连接队列。该处理器会为每个传入的 HttpRequest 向每通道的 validExtensions 队列提供入口,但仅在应用程序写入 HttpResponse 时才从队列中取出条目,且队列大小从未进行限制。远程未认证的peer可以通过HTTP/1.1管道化技术,以比应用程序生成响应更快的速度发送请求(包括发往任意路径的普通非升级HTTP请求),导致队列无限增长

CVSS 5.3 · Medium EPSS 0.35% · P26
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100658

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler
Source: CVE Program / CVE List V5
Vulnerability Description
Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue in WebSocketServerExtensionHandler. The handler offers an entry to its per-channel validExtensions queue for every inbound HttpRequest, but polls an entry only when the application writes an HttpResponse, and the queue size is never bounded. A remote, unauthenticated peer can use HTTP/1.1 pipelining to send requests faster than the application produces responses — including plain non-upgrade HTTP requests to any path — causing the queue to grow without limit until the JVM exhausts heap memory and terminates with OutOfMemoryError. Because the affected handler is the base class of WebSocketServerCompressionHandler, any server that enables permessage-deflate is exposed on its plain HTTP port before any WebSocket upgrade completes and before any application-level authentication. Affected versions are 4.1.88.Final through 4.1.137.Final and 4.2.0.Final through 4.2.17.Final; the issue is fixed in 4.1.138.Final and 4.2.18.Final.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
netty netty 4.1.88.Final ~ 4.1.138.Final -
netty netty 4.2.0.Final ~ 4.2.18.Final -

II. Public POCs for CVE-2026-100658

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100658

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100658 (1)

Other References for CVE-2026-100658 (1)

Same Patch Batch · netty · 2026-09-26 · 12 CVEs total

CVE-2026-100655 7.5 HIGH Netty before 4.1.138.Final Denial of Service via SpdySessionHandler
CVE-2026-100663 7.5 HIGH Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3
CVE-2026-100656 7.5 HIGH Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining
CVE-2026-100661 7.5 HIGH Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation
CVE-2026-100660 7.5 HIGH Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention
CVE-2026-100665 7.5 HIGH Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass
CVE-2026-100662 7.5 HIGH Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS
CVE-2026-100664 7.5 HIGH Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion
CVE-2026-100657 7.5 HIGH Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder
CVE-2026-100666 7.3 HIGH Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec
CVE-2026-100659 6.5 MEDIUM Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-100658

No comments yet


Leave a comment