QSearchQSearch

CVE-2026-46340

7.5 HIGH

Netty is a network application framework for development of protocol servers and clients

Published: 2026-06-12 · Last updated: 2026-06-12

Severity and scoring

CVSS
7.5 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-770

Description

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding references and component arrays; readableBytes()/getBytes() on the final buffer recurse N levels. There is no limit on N, on total bytes, or on the number of streamIdentifiers an attacker can open (each gets its own map entry). A peer that never sets the `complete` flag can grow this structure indefinitely from tiny 1-byte DATA chunks. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-53522 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool (6.5 MEDIUM)
  • CVE-2026-50560 Netty is a network application framework for development of protocol servers and clients
  • CVE-2026-50011 Netty is a network application framework for development of protocol servers and clients (7.5 HIGH)
  • CVE-2026-48748 Netty is a network application framework for development of protocol servers and clients (7.5 HIGH)
  • CVE-2026-45416 Netty is a network application framework for development of protocol servers and clients (7.5 HIGH)