← Zurück zur CVE-Suche

CVE-2026-55851

Netty

Beschreibung

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty-s `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder-s need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS 7.5EPSS 0.612%Risiko 0.79
Quelle öffnen
Veröffentlicht
2026-07-21 22:17:14
Betroffene Versionen
<4.1.136, <4.2.16
Typ
Bibliothek
Zuletzt geändert
2026-07-30 14:48:31
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H