Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | io.netty/netty-codec-http: Netty: Denial of Service via unbounded queue growth during HTTP request pipelining | Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining |
Mon, 28 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining | io.netty/netty-codec-http: Netty: Denial of Service via unbounded queue growth during HTTP request pipelining |
| Metrics |
cvssV4_0
|
Mon, 28 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but every additional entry is appended to methodOverflowQueue, an ArrayDeque with no size limit and no rejection path. A remote, unauthenticated attacker who pipelines HTTP/1.1 requests on a single connection while withholding reads on their own end (preventing responses from being flushed) can grow this queue without bound, causing unbounded heap growth and denial of service. Affected versions are 4.2.0.Final through 4.2.17.Final and all releases up to and including 4.1.137.Final; the issue is fixed in 4.2.18.Final and 4.1.138.Final. | This CVE ID has been rejected as a duplicate. |
| CPEs | ||
| Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 28 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but every additional entry is appended to methodOverflowQueue, an ArrayDeque with no size limit and no rejection path. A remote, unauthenticated attacker who pipelines HTTP/1.1 requests on a single connection while withholding reads on their own end (preventing responses from being flushed) can grow this queue without bound, causing unbounded heap growth and denial of service. Affected versions are 4.2.0.Final through 4.2.17.Final and all releases up to and including 4.1.137.Final; the issue is fixed in 4.2.18.Final and 4.1.138.Final. | |
| Title | Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining | |
| First Time appeared |
Netty
Netty netty |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netty
Netty netty |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T20:59:52.841Z
Reserved: 2026-09-26T02:33:59.038Z
Link: CVE-2026-100656
Updated: 2026-09-28T16:44:17.135Z
Status : Rejected
Published: 2026-09-26T14:16:48.390
Modified: 2026-09-28T22:17:30.207
Link: CVE-2026-100656
OpenCVE Enrichment
No data.
-
CWE-770
Allocation of Resources Without Limits or Throttling