7.5
CVE-2026-59902
- EPSS 0.68%
- Veröffentlicht 17.08.2026 17:48:55
- Zuletzt bearbeitet 18.08.2026 15:16:55
- CVE-Watchlists
- Unerledigt
Netty: Memory Exhaustion in SctpMessageCompletionHandler
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellernetty
≫
Produkt
netty
Version
< 4.1.137.Final
Status
affected
Version
>= 4.2.0.Final, < 4.2.17.Final
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.68% | 0.496 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://github.com/netty/netty/security/advisories/GHSA-2qj4-mmr9-4v2f
https://github.com/netty/netty/pull/17213
https://github.com/netty/netty/pull/17217
https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7
https://github.com/netty/netty/releases/tag/netty-4.1.137.Final
https://github.com/netty/netty/releases/tag/netty-4.2.17.Final