{"id":"CVE-2026-56816","title":"io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 (CVE-2026-56816)","summary":"A flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-770","CWE-400"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["openshift_ai_rhoai"],"patched":["io.netty:netty-codec-http3 4.2.16.Final"],"published":"2026-07-21","updated":"2026-09-15","sourceUpdated":"2026-09-15T04:52:45+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56816.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56816.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-56816"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2505424"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-56816"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56816"},{"url":"https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"},{"url":"https://github.com/netty/netty/security/advisories/GHSA-hpcc-26xq-25fv"},{"url":"https://github.com/advisories/GHSA-hpcc-26xq-25fv"}],"tags":["csaf","vex","red-hat","ghsa","maven"],"epss":0.00522,"epssPercentile":0.431,"aliases":["GHSA-hpcc-26xq-25fv"],"ecosystem":"maven","ingestedAt":"2026-07-22T22:06:57.819Z","slug":"CVE-2026-56816","body":"## Overview\n\nA flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory buffering, causing memory exhaustion and a denial of service (DoS) for the affected system.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat OpenShift AI (RHOAI) · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56816.json)\n\n**io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3** — rated Important by Red Hat. Released 2026-07-21, updated 2026-09-15.\n\nAffected:\n\n- Red Hat OpenShift AI (RHOAI)\n\nNo fix planned:\n\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat OpenShift Dev Spaces\n\n## Remediation\n\nAffected\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-56816)\n\nAffected packages:\n\n- `io.netty:netty-codec-http3 < 4.2.16.Final`\n\nPatched in:\n\n- `io.netty:netty-codec-http3 4.2.16.Final`\n\nSource: https://github.com/advisories/GHSA-hpcc-26xq-25fv","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}