QID 982253

QID 982253: Java (maven) Security Update for io.netty:netty-handler (GHSA-mm9x-g8pc-w292)

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-mm9x-g8pc-w292 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982253

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mm9x-g8pc-w292 io.netty:netty-handler URL Logo github.com/advisories/GHSA-mm9x-g8pc-w292