{"id":"CVE-2026-73508","title":"Netty is an asynchronous, event-driven network application framework","summary":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-772"],"published":"2026-08-13","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:58:37.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73508","references":[{"url":"https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","label":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","label":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","label":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","label":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73508.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-73508"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515377"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73508"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73508"},{"url":"https://access.redhat.com/errata/RHSA-2026:68754"},{"url":"https://access.redhat.com/errata/RHSA-2026:69296"}],"tags":["nvd","csaf","vex","red-hat","score-dispute"],"epss":0.00333,"epssPercentile":0.26638,"ingestedAt":"2026-09-09T21:22:45.533Z","vendor":"Red Hat","product":"OpenShift Serverless","affected":["exploit_intelligence","openshift_serverless","build_of_apicurio_registry 3","build_of_debezium 3","build_of_keycloak","data_grid 8","enterprise_linux_ai_rhel_ai 3","jboss_enterprise_application_platform 7","jboss_enterprise_application_platform 8","jboss_enterprise_application_platform_expansion_pack","openshift_ai_rhoai","openshift_dev_spaces","single_sign_on 7","openshift_dev_spaces 3.30"],"patched":["openshift_dev_spaces 3.30"],"scores":{"nvd":5.3,"vendor":7.5},"slug":"CVE-2026-73508","body":"## Overview\n\nNetty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:68754** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68754)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, OpenShift Serverless, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat Data Grid 8, … · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Exploit Intelligence, OpenShift Serverless, Red Hat build of Apicurio Registry 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73508.json)\n- **RHSA-2026:69296** · Red Hat · fixed in: Red Hat Data Grid 8.6.3 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69296)","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}