CVE-2026-100658

Source
https://cve.org/CVERecord?id=CVE-2026-100658
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100658.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100658
Aliases
  • GHSA-2g37-3h88-55hc
Published
2026-09-26T13:23:26Z
Modified
2026-09-28T03:30:47Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler
Details

Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue in WebSocketServerExtensionHandler. The handler offers an entry to its per-channel validExtensions queue for every inbound HttpRequest, but polls an entry only when the application writes an HttpResponse, and the queue size is never bounded. A remote, unauthenticated peer can use HTTP/1.1 pipelining to send requests faster than the application produces responses — including plain non-upgrade HTTP requests to any path — causing the queue to grow without limit until the JVM exhausts heap memory and terminates with OutOfMemoryError. Because the affected handler is the base class of WebSocketServerCompressionHandler, any server that enables permessage-deflate is exposed on its plain HTTP port before any WebSocket upgrade completes and before any application-level authentication. Affected versions are 4.1.88.Final through 4.1.137.Final and 4.2.0.Final through 4.2.17.Final; the issue is fixed in 4.1.138.Final and 4.2.18.Final.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-770"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100658.json"
}
References

Affected packages

Git / github.com/netty/netty

Affected ranges

Type
GIT
Repo
https://github.com/netty/netty
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "4.1.88.Final"
        },
        {
            "fixed":  "4.1.138.Final"
        },
        {
            "introduced":  "4.2.0.Final"
        },
        {
            "fixed":  "4.2.18.Final"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

netty-4.*
netty-4.1.100.Final
netty-4.1.101.Final
netty-4.1.102.Final
netty-4.1.103.Final
netty-4.1.104.Final
netty-4.1.105.Final
netty-4.1.106.Final
netty-4.1.107.Final
netty-4.1.108.Final
netty-4.1.109.Final
netty-4.1.110.Final
netty-4.1.111.Final
netty-4.1.112.Final
netty-4.1.113.Final
netty-4.1.114.Final
netty-4.1.115.Final
netty-4.1.116.Final
netty-4.1.117.Final
netty-4.1.118.Final
netty-4.1.119.Final
netty-4.1.120.Final
netty-4.1.121.Final
netty-4.1.122.Final
netty-4.1.123.Final
netty-4.1.124.Final
netty-4.1.125.Final
netty-4.1.126.Final
netty-4.1.127.Final
netty-4.1.128.Final
netty-4.1.129.Final
netty-4.1.130.Final
netty-4.1.131.Final
netty-4.1.132.Final
netty-4.1.133.Final
netty-4.1.134.Final
netty-4.1.135.Final
netty-4.1.136.Final
netty-4.1.137.Final
netty-4.1.88.Final
netty-4.1.89.Final
netty-4.1.90.Final
netty-4.1.91.Final
netty-4.1.92.Final
netty-4.1.93.Final
netty-4.1.94.Final
netty-4.1.95.Final
netty-4.1.96.Final
netty-4.1.97.Final
netty-4.1.98.Final
netty-4.1.99.Final
netty-4.2.0.Final
netty-4.2.1.Final
netty-4.2.10.Final
netty-4.2.11.Final
netty-4.2.12.Final
netty-4.2.13.Final
netty-4.2.14.Final
netty-4.2.15.Final
netty-4.2.16.Final
netty-4.2.17.Final
netty-4.2.2.Final
netty-4.2.3.Final
netty-4.2.4.Final
netty-4.2.5.Final
netty-4.2.6.Final
netty-4.2.7.Final
netty-4.2.8.Final
netty-4.2.9.Final
Other
netty-clang-bin

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100658.json"