CVE-2026-55831

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*

History

23 Jul 2026, 15:17

Type Values Removed Values Added
References () https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w - Exploit, Vendor Advisory () https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w - Exploit, Vendor Advisory

22 Jul 2026, 19:37

Type Values Removed Values Added
References () https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b - () https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b - Patch
References () https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 - () https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 - Patch
References () https://github.com/netty/netty/releases/tag/netty-4.1.136.Final - () https://github.com/netty/netty/releases/tag/netty-4.1.136.Final - Release Notes
References () https://github.com/netty/netty/releases/tag/netty-4.2.16.Final - () https://github.com/netty/netty/releases/tag/netty-4.2.16.Final - Release Notes
References () https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w - () https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w - Exploit, Vendor Advisory
CPE cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
First Time Netty netty
Netty

21 Jul 2026, 00:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-21 00:17

Updated : 2026-07-23 15:17


NVD link : CVE-2026-55831

Mitre link : CVE-2026-55831

CVE.ORG link : CVE-2026-55831


JSON object : View

Products Affected

netty

  • netty
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling