Denial of Service Vulnerability in Netty Framework by Netty
CVE-2026-59902
7.5HIGH
What is CVE-2026-59902?
The Netty Framework, an asynchronous and event-driven network application framework, has a vulnerability that allows unauthenticated peers to exhaust memory by sending large SCTP fragments. This occurs due to insufficient limits on maxBufferedBytes in the SctpMessageCompletionHandler prior to versions 4.1.137.Final and 4.2.17.Final. The issue has been addressed in the specified versions, ensuring enhanced stability and security against potential memory exhaustion attacks.
Affected Version(s)
netty < 4.1.137.Final < 4.1.137.Final
netty >= 4.2.0.Final, < 4.2.17.Final < 4.2.0.Final, 4.2.17.Final
