{"id":"CVE-2026-59901","title":"io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) (CVE-2026-59901)","summary":"A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-835","vendor":"Red Hat","product":"Red Hat build of Apache Camel - HawtIO 4","affected":["build_of_apache_camel_hawtio 4","openshift_dev_spaces","data_grid 8.6.3","streams_for_apache_kafka 3.2.1"],"patched":["data_grid 8.6.3","streams_for_apache_kafka 3.2.1"],"published":"2026-07-09","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:20:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59901.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59901.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59901"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507481"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59901"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59901"},{"url":"https://access.redhat.com/errata/RHSA-2026:69296"},{"url":"https://access.redhat.com/errata/RHSA-2026:54435"},{"url":"https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"},{"url":"https://github.com/advisories/GHSA-558v-64gr-wgg4"}],"tags":["csaf","vex","red-hat","ghsa","maven"],"epss":0.00263,"epssPercentile":0.18442,"aliases":["GHSA-558v-64gr-wgg4"],"ecosystem":"maven","ingestedAt":"2026-07-22T22:06:57.636Z","slug":"CVE-2026-59901","body":"## Overview\n\nA flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data can trigger an infinite loop, causing the decoder thread to consume excessive CPU resources. This leads to a denial of service (DoS), requiring manual intervention to restore service.\n\n## Vendor advisories\n\n- **RHSA-2026:69296** · Red Hat · fixed in: Red Hat Data Grid 8.6.3 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69296)\n- **RHSA-2026:54435** · Red Hat · fixed in: Streams for Apache Kafka 3.2.1 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54435)\n- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift Dev Spaces · no fix planned: Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift Dev Spaces · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59901.json)\n\n**io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)** — rated Important by Red Hat. Released 2026-07-09, updated 2026-09-21.\n\nAffected:\n\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat OpenShift Dev Spaces\n\nFixed:\n\n- Red Hat Data Grid 8.6.3\n- Streams for Apache Kafka 3.2.1\n\nNo fix planned:\n\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat OpenShift Dev Spaces\n\nNot affected:\n\n- Red Hat JBoss Enterprise Application Platform Expansion Pack\n- Red Hat OpenShift Dev Spaces\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:69296\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54435\n\n## Package advisory (CVE-2026-59901)\n\nAffected packages:\n\n- `io.netty:netty-codec-compression >= 4.2.0.Final, < 4.2.16.Final`\n- `io.netty:netty-codec < 4.1.136.Final`\n\nPatched in:\n\n- `io.netty:netty-codec-compression 4.2.16.Final`\n- `io.netty:netty-codec 4.1.136.Final`\n\nSource: https://github.com/advisories/GHSA-558v-64gr-wgg4","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208566,"id":"CVE-2026-59901","ts":1790009096106,"field":"cvss","old":null,"new":"7.5"}]}