---
id: CVE-2026-56816
title: >-
  io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled
  memory buffering in HTTP/3 (CVE-2026-56816)
summary: >-
  A flaw was found in Netty. An unauthenticated remote attacker can exploit a
  vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3
  reserved frames with excessive payload lengths. This can lead to uncontrolled
  memory…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-770
  - CWE-400
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - openshift_ai_rhoai
patched:
  - 'io.netty:netty-codec-http3 4.2.16.Final'
published: '2026-07-21'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T04:52:45+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56816.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56816.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-56816'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2505424'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-56816'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56816'
  - url: >-
      https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.2.16.Final'
  - url: 'https://github.com/netty/netty/security/advisories/GHSA-hpcc-26xq-25fv'
  - url: 'https://github.com/advisories/GHSA-hpcc-26xq-25fv'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - maven
epss: 0.00644
epssPercentile: 0.48679
aliases:
  - GHSA-hpcc-26xq-25fv
ecosystem: maven
ingestedAt: '2026-07-22T22:06:57.819Z'
---

## Overview

A flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory buffering, causing memory exhaustion and a denial of service (DoS) for the affected system.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat OpenShift AI (RHOAI) · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56816.json)

**io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3** — rated Important by Red Hat. Released 2026-07-21, updated 2026-09-15.

Affected:

- Red Hat OpenShift AI (RHOAI)

No fix planned:

- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat OpenShift Dev Spaces

## Remediation

Affected

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-56816)

Affected packages:

- `io.netty:netty-codec-http3 < 4.2.16.Final`

Patched in:

- `io.netty:netty-codec-http3 4.2.16.Final`

Source: https://github.com/advisories/GHSA-hpcc-26xq-25fv
