---
id: CVE-2026-55851
title: >-
  io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via
  crafted PROXY protocol v2 message (CVE-2026-55851)
summary: >-
  A flaw was found in Netty's codec-haproxy module. A remote attacker could
  exploit a vulnerability in the HAProxyMessageDecoder by sending a specially
  crafted PROXY protocol v2 message. This leads to unbounded buffer
  accumulation, causing a…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-770
  - CWE-400
vendor: Red Hat
product: OpenShift Serverless
affected:
  - openshift_serverless
  - build_of_apache_camel_hawtio 4
  - build_of_apache_camel_4_for_quarkus 3
  - build_of_apicurio_registry 3
  - build_of_debezium 3
  - build_of_keycloak
  - jboss_enterprise_application_platform 7
  - openshift_dev_spaces
  - single_sign_on 7
  - streams_for_apache_kafka 2
  - streams_for_apache_kafka 3
  - cryostat_4_on_rhel 9
  - amq_broker 7.14.1
  - data_grid 8.6.3
  - openshift_ai 2.25
  - build_of_apache_camel_4_18_3_for_spring_boot 3.5.16
  - build_of_quarkus 3.27.4.SP3
  - build_of_quarkus 3.33.2.SP3
patched:
  - cryostat_4_on_rhel 9
  - amq_broker 7.14.1
  - data_grid 8.6.3
  - openshift_ai 2.25
  - build_of_apache_camel_4_18_3_for_spring_boot 3.5.16
  - build_of_quarkus 3.27.4.SP3
  - build_of_quarkus 3.33.2.SP3
published: '2026-07-21'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T15:29:03+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55851.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55851.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-55851'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2505698'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-55851'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55851'
  - url: >-
      https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b
  - url: >-
      https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.1.136.Final'
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.2.16.Final'
  - url: 'https://github.com/netty/netty/security/advisories/GHSA-q6cq-mhr2-jmr5'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68333'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66488'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69296'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54622'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47189'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47172'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48118'
  - url: 'https://github.com/advisories/GHSA-q6cq-mhr2-jmr5'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - maven
epss: 0.0063
epssPercentile: 0.47957
aliases:
  - GHSA-q6cq-mhr2-jmr5
ecosystem: maven
ingestedAt: '2026-07-22T22:06:58.003Z'
---

## Overview

A flaw was found in Netty's codec-haproxy module. A remote attacker could exploit a vulnerability in the HAProxyMessageDecoder by sending a specially crafted PROXY protocol v2 message. This leads to unbounded buffer accumulation, causing a denial of service (DoS) due to memory exhaustion.

## Vendor advisories

- **RHSA-2026:68333** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68333)
- **RHSA-2026:66488** · Red Hat · fixed in: Red Hat AMQ Broker 7.14.1 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66488)
- **RHSA-2026:69296** · Red Hat · fixed in: Red Hat Data Grid 8.6.3 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69296)
- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)
- **RHSA-2026:54622** · Red Hat · fixed in: Red Hat build of Apache Camel 4.18.3 for Spring Boot 3.5.16 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54622)
- **RHSA-2026:47189** · Red Hat · fixed in: Red Hat build of Quarkus 3.27.4.SP3 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:47189)
- **RHSA-2026:47172** · Red Hat · fixed in: Red Hat build of Quarkus 3.33.2.SP3 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:47172)
- **Red Hat VEX** · Important · affected: OpenShift Serverless, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, … · no fix planned: Red Hat build of Debezium 3, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, OpenShift Serverless, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55851.json)
- **RHSA-2026:48118** · Red Hat · fixed in: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48118)

**io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message** — rated Important by Red Hat. Released 2026-07-21, updated 2026-09-25.

Affected:

- OpenShift Serverless
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apache Camel 4 for Quarkus 3
- Red Hat build of Apicurio Registry 3
- Red Hat build of Debezium 3
- Red Hat Build of Keycloak
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat OpenShift Dev Spaces
- Red Hat Single Sign-On 7
- streams for Apache Kafka 2
- streams for Apache Kafka 3

Fixed:

- Cryostat 4 on RHEL 9
- Red Hat AMQ Broker 7.14.1
- Red Hat Data Grid 8.6.3
- Red Hat OpenShift AI 2.25
- Red Hat build of Apache Camel 4.18.3 for Spring Boot 3.5.16
- Red Hat build of Quarkus 3.27.4.SP3
- Red Hat build of Quarkus 3.33.2.SP3

No fix planned:

- Red Hat build of Debezium 3
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat Single Sign-On 7
- OpenShift Serverless
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apache Camel 4 for Quarkus 3
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Keycloak
- Red Hat OpenShift Dev Spaces
- streams for Apache Kafka 2
- streams for Apache Kafka 3

Not affected:

- Cryostat 4 on RHEL 9
- Red Hat OpenShift AI 2.25
- Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Satellite 6

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.

The References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66488
Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:69296

## Package advisory (CVE-2026-55851)

Affected packages:

- `io.netty:netty-codec-haproxy >= 4.2.0.Final, <= 4.2.15.Final`
- `io.netty:netty-codec-haproxy >= 4.1.0.Final, <= 4.1.135.Final`

Patched in:

- `io.netty:netty-codec-haproxy 4.2.16.Final`
- `io.netty:netty-codec-haproxy 4.1.136.Final`

Source: https://github.com/advisories/GHSA-q6cq-mhr2-jmr5
