Uncontrolled Resource Consumption in Netty HTTP/3 Codec Affects Netty
CVE-2026-100662
8.7HIGH
What is CVE-2026-100662?
The Netty HTTP/3 codec is vulnerable to an uncontrolled resource consumption issue due to inadequate limits on input lengths in the QPACK encoder's stream instruction decoder. An attacker can exploit this vulnerability by establishing a remote connection and declaring excessively large lengths for string literals in the 'Insert With Literal Name' instruction. As a result, the handler can lead to unbounded heap growth, potentially causing an OutOfMemoryError and subsequent denial of service. This vulnerability impacts versions 4.2.0.Final through 4.2.17.Final and has been addressed in version 4.2.18.Final.
Affected Version(s)
netty 4.2.0.Final < 4.2.18.Final
netty 4.2.18.Final
