---
id: CVE-2026-59901
title: >-
  io.netty/netty-codec-compression: Netty: Infinite loop in
  netty-codec-compression (bzip2) (CVE-2026-59901)
summary: >-
  A flaw was found in the netty-codec-compression component of Netty. This
  vulnerability, caused by a logic error in the bzip2 decoder, allows a remote
  attacker to send specially crafted bzip2-compressed data. Processing this
  malformed data …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-835
vendor: Red Hat
product: Red Hat build of Apache Camel - HawtIO 4
affected:
  - build_of_apache_camel_hawtio 4
  - openshift_dev_spaces
  - data_grid 8.6.3
  - streams_for_apache_kafka 3.2.1
patched:
  - data_grid 8.6.3
  - streams_for_apache_kafka 3.2.1
published: '2026-07-09'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:20:38+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59901.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59901.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59901'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2507481'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59901'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59901'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69296'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54435'
  - url: 'https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4'
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.1.136.Final'
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.2.16.Final'
  - url: 'https://github.com/advisories/GHSA-558v-64gr-wgg4'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - maven
epss: 0.0046
epssPercentile: 0.3714
aliases:
  - GHSA-558v-64gr-wgg4
ecosystem: maven
ingestedAt: '2026-07-22T22:06:57.636Z'
---

## Overview

A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data can trigger an infinite loop, causing the decoder thread to consume excessive CPU resources. This leads to a denial of service (DoS), requiring manual intervention to restore service.

## Vendor advisories

- **RHSA-2026:69296** · Red Hat · fixed in: Red Hat Data Grid 8.6.3 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69296)
- **RHSA-2026:54435** · Red Hat · fixed in: Streams for Apache Kafka 3.2.1 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54435)
- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift Dev Spaces · no fix planned: Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift Dev Spaces · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59901.json)

**io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)** — rated Important by Red Hat. Released 2026-07-09, updated 2026-09-21.

Affected:

- Red Hat build of Apache Camel - HawtIO 4
- Red Hat OpenShift Dev Spaces

Fixed:

- Red Hat Data Grid 8.6.3
- Streams for Apache Kafka 3.2.1

No fix planned:

- Red Hat build of Apache Camel - HawtIO 4
- Red Hat OpenShift Dev Spaces

Not affected:

- Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat OpenShift Dev Spaces

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:69296
Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54435

## Package advisory (CVE-2026-59901)

Affected packages:

- `io.netty:netty-codec-compression >= 4.2.0.Final, < 4.2.16.Final`
- `io.netty:netty-codec < 4.1.136.Final`

Patched in:

- `io.netty:netty-codec-compression 4.2.16.Final`
- `io.netty:netty-codec 4.1.136.Final`

Source: https://github.com/advisories/GHSA-558v-64gr-wgg4
