DDoS Vulnerability in Netty Framework
CVE-2025-55163

8.2HIGH

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
13 August 2025

What is CVE-2025-55163?

The Netty Framework, known for its asynchronous and event-driven capabilities, is susceptible to a logical vulnerability affecting the HTTP/2 protocol. This flaw allows an attacker to exploit malformed HTTP/2 control frames, thereby manipulating the maximum concurrent streams limit. Such exploitation can lead to resource exhaustion, ultimately resulting in a Distributed Denial of Service (DDoS) condition. Users of Netty are advised to update to versions 4.1.124.Final or 4.2.4.Final, where this vulnerability has been addressed.

Affected Version(s)

netty < 4.1.124.Final < 4.1.124.Final

netty < 4.2.4.Final < 4.2.4.Final

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55163 : DDoS Vulnerability in Netty Framework