CVE-2026-59901High· 7.5▾ TwilightA flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 30.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.3%
Last analysed / modified upstream
— → 7.5
A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data can trigger an infinite loop, causing the decoder thread to consume excessive CPU resources. This leads to a denial of service (DoS), requiring manual intervention to restore service.
io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) — rated Important by Red Hat. Released 2026-07-09, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:69296 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54435
Affected packages:
io.netty:netty-codec-compression >= 4.2.0.Final, < 4.2.16.Finalio.netty:netty-codec < 4.1.136.FinalPatched in:
io.netty:netty-codec-compression 4.2.16.Finalio.netty:netty-codec 4.1.136.FinalField changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90816Medium· 4.3A vulnerability was found in FFmpeg 8.0.x
CVE-2026-89567Medium· 5.5kernel: jbd2: bound shrinker scans by examined checkpoint buffers (CVE-2026-89567)
CVE-2026-89578Medium· 5.5kernel: dm-io: clone the source bio instead of copying its biovec (CVE-2026-89578)
CVE-2026-80957Medium· 5.5kernel: dm-pcache: detect a cycle in the last-kset chain during replay (CVE-2026-80957)
CVE-2021-33194High· 7.5golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)
CVE-2020-14040High· 7.5golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)