Memory Exhaustion Vulnerability in Netty's HTTP/3 Functionality
CVE-2026-56816

7.5HIGH

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-56816?

The Netty framework is susceptible to a vulnerability in its Http3FrameCodec. This flaw allows an attacker to exploit the way the framework handles incoming data for certain HTTP/3 reserved frame types. By sending large payloads that exceed safe limits, an attacker can open multiple QUIC streams, leading to memory exhaustion and potentially causing denial of service to legitimate users. This issue has been addressed in version 4.2.16.Final.

Affected Version(s)

netty < 4.2.16.Final

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.