Denial of Service Vulnerability in Netty Framework by Netty
CVE-2026-59902

7.5HIGH

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-59902?

The Netty Framework, an asynchronous and event-driven network application framework, has a vulnerability that allows unauthenticated peers to exhaust memory by sending large SCTP fragments. This occurs due to insufficient limits on maxBufferedBytes in the SctpMessageCompletionHandler prior to versions 4.1.137.Final and 4.2.17.Final. The issue has been addressed in the specified versions, ensuring enhanced stability and security against potential memory exhaustion attacks.

Affected Version(s)

netty < 4.1.137.Final < 4.1.137.Final

netty >= 4.2.0.Final, < 4.2.17.Final < 4.2.0.Final, 4.2.17.Final

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.