← Back to CVE search

CVE-2026-59902

Netty

Description

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.

CVSS 7.5EPSS 0.371%Risk 0.78
View source
Published
2026-08-17 18:17:36
Affected versions
cannotmatch
Type
Library
Last modified
2026-08-18 15:16:55
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H