---
id: CVE-2026-59902
title: 'Netty is an asynchronous, event-driven network application framework'
summary: >-
  Netty is an asynchronous, event-driven network application framework. Prior to
  4.1.137.Final and 4.2.17.Final,
  io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete
  messages and fragment counts but not maxBufferedByt…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-770
vendor: netty
product: netty
affected:
  - netty < 4.1.137
  - 'netty >= 4.2.0, < 4.2.17'
patched:
  - netty 4.2.17
published: '2026-08-17'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T15:31:54.467'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59902'
references:
  - url: >-
      https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7
    label: security-advisories@github.com
  - url: 'https://github.com/netty/netty/pull/17213'
    label: security-advisories@github.com
  - url: 'https://github.com/netty/netty/pull/17217'
    label: security-advisories@github.com
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.1.137.Final'
    label: security-advisories@github.com
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.2.17.Final'
    label: security-advisories@github.com
  - url: 'https://github.com/netty/netty/security/advisories/GHSA-2qj4-mmr9-4v2f'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-2qj4-mmr9-4v2f'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59902.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59902'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2517526'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59902'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59902'
tags:
  - nvd
  - ghsa
  - maven
  - csaf
  - vex
  - red-hat
epss: 0.00371
epssPercentile: 0.31038
aliases:
  - GHSA-2qj4-mmr9-4v2f
ecosystem: maven
ingestedAt: '2026-08-17T17:58:09.844Z'
---

## Overview

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.

## Affected

- `netty < 4.1.137`
- `netty >= 4.2.0, < 4.2.17`

## Remediation

Upgrade past the affected range:

- `netty 4.2.17`

## Package advisory (CVE-2026-59902)

Affected packages:

- `io.netty:netty-transport-sctp >= 4.2.0.Final, <= 4.2.16.Final`
- `io.netty:netty-transport-sctp <= 4.1.136.Final`

Patched in:

- `io.netty:netty-transport-sctp 4.2.17.Final`
- `io.netty:netty-transport-sctp 4.1.137.Final`

Source: https://github.com/advisories/GHSA-2qj4-mmr9-4v2f

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel for Spring Boot 4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Single Sign-On 7 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59902.json)
