Memory Exhaustion Vulnerability in Netty's HTTP/3 Functionality
CVE-2026-56816
7.5HIGH
What is CVE-2026-56816?
The Netty framework is susceptible to a vulnerability in its Http3FrameCodec. This flaw allows an attacker to exploit the way the framework handles incoming data for certain HTTP/3 reserved frame types. By sending large payloads that exceed safe limits, an attacker can open multiple QUIC streams, leading to memory exhaustion and potentially causing denial of service to legitimate users. This issue has been addressed in version 4.2.16.Final.
Affected Version(s)
netty < 4.2.16.Final
