7.5

CVE-2026-59902

Netty: Memory Exhaustion in SctpMessageCompletionHandler

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netty ≫ Netty Version < 4.1.137
Netty ≫ Netty Version >= 4.2.0 < 4.2.17
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.68% 0.496
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://github.com/netty/netty/security/advisories/GHSA-2qj4-mmr9-4v2f
Vendor Advisory
https://github.com/netty/netty/pull/17213
Patch
Issue Tracking
https://github.com/netty/netty/pull/17217
Patch
Issue Tracking
https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7
Patch
https://github.com/netty/netty/releases/tag/netty-4.1.137.Final
Release Notes
https://github.com/netty/netty/releases/tag/netty-4.2.17.Final
Release Notes