CVE-2026-56816High· 7.5▾ TwilightA flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.6%
Last analysed / modified upstream
A flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's Http3FrameCodec by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory buffering, causing memory exhaustion and a denial of service (DoS) for the affected system.
io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 — rated Important by Red Hat. Released 2026-07-21, updated 2026-09-15.
Affected:
No fix planned:
Not affected:
Affected
Workarounds / mitigations:
Affected packages:
io.netty:netty-codec-http3 < 4.2.16.FinalPatched in:
io.netty:netty-codec-http3 4.2.16.FinalConnected by shared product, vendor, weakness, or advisory.
CVE-2026-86250High· 7.5h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions
CVE-2026-81725Medium· 5.9nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)
CVE-2026-67317Medium· 5.3axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined
CVE-2025-69228Medium· 6.8aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request (CVE-2025-69228)
CVE-2026-49855High· 7.5tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)
CVE-2026-59888Medium· 6.5com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records (CVE…