Netty是Netty团队开源的一款非阻塞I/O客户端-服务器框架,它主要用于开发Java网络应用程序,如协议服务器和客户端等。 Netty 4.1.136.Final之前版本和4.2.16.Final之前版本存在资源管理错误漏洞,该漏洞源于压缩编解码器管道中的Bzip2Decoder处理器存在缺陷,通过畸形的bzip2流导致事件循环线程陷入无限循环,容易受到拒绝服务攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-59899 | 6.9 MEDIUM | Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Le |
| CVE-2026-59900 | 6.9 MEDIUM | Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads |
| CVE-2026-59920 | 6.5 MEDIUM | Netty: STOMP CONNECT Frame Header Injection |
| CVE-2026-59898 | 6.3 MEDIUM | Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation |
| CVE-2026-59919 | 5.5 MEDIUM | Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address |
No comments yet