Uncontrolled Resource Consumption in Netty HTTP/3 Codec Affects Netty
CVE-2026-100662

8.7HIGH

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100662?

The Netty HTTP/3 codec is vulnerable to an uncontrolled resource consumption issue due to inadequate limits on input lengths in the QPACK encoder's stream instruction decoder. An attacker can exploit this vulnerability by establishing a remote connection and declaring excessively large lengths for string literals in the 'Insert With Literal Name' instruction. As a result, the handler can lead to unbounded heap growth, potentially causing an OutOfMemoryError and subsequent denial of service. This vulnerability impacts versions 4.2.0.Final through 4.2.17.Final and has been addressed in version 4.2.18.Final.

Affected Version(s)

netty 4.2.0.Final < 4.2.18.Final

netty 4.2.18.Final

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.