๐Ÿ” CVE Alert

CVE-2026-56745

UNKNOWN 0.0

Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CWE CWE-400
Vendor netty
Product netty
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for netty netty

Be the first to know when new unknown vulnerabilities affecting netty netty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

netty / netty
>= 4.2.0.Final, < 4.2.16.Final >= 4.1.0.Final, < 4.1.136.Final

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq github.com: https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b github.com: https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 github.com: https://github.com/netty/netty/releases/tag/netty-4.1.136.Final github.com: https://github.com/netty/netty/releases/tag/netty-4.2.16.Final