Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | io.netty/netty-codec-http: Netty: Denial of Service via unbounded SPDY concurrent streams | Netty before 4.1.138.Final Denial of Service via SpdySessionHandler |
Mon, 28 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Netty before 4.1.138.Final Denial of Service via SpdySessionHandler | io.netty/netty-codec-http: Netty: Denial of Service via unbounded SPDY concurrent streams |
| Metrics |
cvssV4_0
|
Mon, 28 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: SpdySessionHandler defaults localConcurrentStreams to Integer.MAX_VALUE and exposes no API to change it. A remote peer that opens a SPDY connection and sends millions of SYN_STREAM frames with FLAG_FIN=0 causes the server to allocate unbounded heap and direct memory, eventually triggering a JVM OutOfMemoryError and crashing the service. Fixed in 4.1.138.Final and 4.2.18.Final. | This CVE ID has been rejected as a duplicate. |
| CPEs | ||
| Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 28 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: SpdySessionHandler defaults localConcurrentStreams to Integer.MAX_VALUE and exposes no API to change it. A remote peer that opens a SPDY connection and sends millions of SYN_STREAM frames with FLAG_FIN=0 causes the server to allocate unbounded heap and direct memory, eventually triggering a JVM OutOfMemoryError and crashing the service. Fixed in 4.1.138.Final and 4.2.18.Final. | |
| Title | Netty before 4.1.138.Final Denial of Service via SpdySessionHandler | |
| First Time appeared |
Netty
Netty netty |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netty
Netty netty |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T20:59:52.595Z
Reserved: 2026-09-26T02:33:07.899Z
Link: CVE-2026-100655
Updated: 2026-09-28T18:19:30.927Z
Status : Rejected
Published: 2026-09-26T14:16:48.243
Modified: 2026-09-28T22:17:30.120
Link: CVE-2026-100655
OpenCVE Enrichment
No data.
-
CWE-770
Allocation of Resources Without Limits or Throttling