CVE-2026-55851High· 7.5▾ TwilightA flaw was found in Netty's codec-haproxy module. A remote attacker could exploit a vulnerability in the HAProxyMessageDecoder by sending a specially crafted PROXY protocol v2 message. This leads to unbounded buffer accumulation, causing a…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
0.5% → 0.6%
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
Last analysed / modified upstream
A flaw was found in Netty's codec-haproxy module. A remote attacker could exploit a vulnerability in the HAProxyMessageDecoder by sending a specially crafted PROXY protocol v2 message. This leads to unbounded buffer accumulation, causing a denial of service (DoS) due to memory exhaustion.
io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message — rated Important by Red Hat. Released 2026-07-21, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333 Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.
The References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66488 Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:48118
Affected packages:
io.netty:netty-codec-haproxy >= 4.2.0.Final, <= 4.2.15.Finalio.netty:netty-codec-haproxy >= 4.1.0.Final, <= 4.1.135.FinalPatched in:
io.netty:netty-codec-haproxy 4.2.16.Finalio.netty:netty-codec-haproxy 4.1.136.FinalField changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73508Medium· 5.3Netty is an asynchronous, event-driven network application framework
CVE-2026-12151High· 7.5undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
CVE-2026-47244Medium· 5.3netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams (CVE-2026-47244)
CVE-2026-50560Medium· 5.3netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling (CVE-2026-50560)
CVE-2026-14257High· 7.5brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
CVE-2026-13149High· 7.5brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)