Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
References
| Link | Resource |
|---|---|
| https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b | Patch |
| https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 | Patch |
| https://github.com/netty/netty/pull/17063 | Issue Tracking Patch |
| https://github.com/netty/netty/pull/17065 | Issue Tracking Patch |
| https://github.com/netty/netty/releases/tag/netty-4.1.136.Final | Release Notes |
| https://github.com/netty/netty/releases/tag/netty-4.2.16.Final | Release Notes |
| https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp | Exploit Vendor Advisory |
| https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Jul 2026, 19:38
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Netty netty
Netty |
|
| CPE | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | |
| References | () https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b - Patch | |
| References | () https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 - Patch | |
| References | () https://github.com/netty/netty/pull/17063 - Issue Tracking, Patch | |
| References | () https://github.com/netty/netty/pull/17065 - Issue Tracking, Patch | |
| References | () https://github.com/netty/netty/releases/tag/netty-4.1.136.Final - Release Notes | |
| References | () https://github.com/netty/netty/releases/tag/netty-4.2.16.Final - Release Notes | |
| References | () https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp - Exploit, Vendor Advisory |
20 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp - |
17 Jul 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-17 21:17
Updated : 2026-07-23 13:35
NVD link : CVE-2026-44891
Mitre link : CVE-2026-44891
CVE.ORG link : CVE-2026-44891
JSON object : View
Products Affected
netty
- netty
