CVE-2026-47244Medium· 5.3▾ SunlitA flaw was found in Netty, a network application framework. A remote attacker can exploit this vulnerability by sending a large number of HTTP/2 stream requests to a Netty HTTP/2 server. If the server does not explicitly limit concurrent s…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
Last analysed / modified upstream
A flaw was found in Netty, a network application framework. A remote attacker can exploit this vulnerability by sending a large number of HTTP/2 stream requests to a Netty HTTP/2 server. If the server does not explicitly limit concurrent streams, it can lead to the allocation of numerous long-lived stream objects. This excessive resource consumption can result in a denial of service (DoS), making the server unavailable to legitimate users.
netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams — rated Moderate by Red Hat. Released 2026-06-12, updated 2026-09-07.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:50085 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:26018 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:26017
Workarounds / mitigations:
Affected packages:
io.netty:netty-codec-http2 >= 4.2.0.Final, <= 4.2.14.Finalio.netty:netty-codec-http2 <= 4.1.134.FinalPatched in:
io.netty:netty-codec-http2 4.2.15.Finalio.netty:netty-codec-http2 4.1.135.FinalConnected by shared product, vendor, weakness, or advisory.
CVE-2026-50560Medium· 5.3netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling (CVE-2026-50560)
CVE-2026-45673Medium· 6.8netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs (CVE-2026-45673)
CVE-2026-50020Medium· 5.3netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder (CVE-2026-50020)
CVE-2026-55851High· 7.5io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851)
CVE-2026-14257High· 7.5brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
CVE-2026-12151High· 7.5undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)