CyberRota Analysis
AI-GeneratedThe vulnerability exists in Netty's HTTP/3 codec, where an unauthenticated remote client can exploit unbounded QPACK encoder state retention, leading to potential denial of service through unbounded heap growth. This occurs as the codec fails to limit the number of tracked streams and retained bytes, allowing attackers to exhaust server memory by bypassing concurrent-stream limits. Organizations using affected versions of Netty (4.2.0.Final to 4.2.17.Final) should prioritize upgrading to version 4.2.18.Final to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID, and these entries are released only when the remote decoder sends a Section Acknowledgment or Stream Cancellation instruction — not when the HTTP/3 stream completes. There is no limit on the number of tracked streams, field sections, or retained bytes. A remote, unauthenticated HTTP/3 client can advertise a non-zero QPACK dynamic-table capacity, acknowledge the table insertion so the server reuses a dynamically indexed response header, and then omit all mandatory Section Acknowledgments while issuing sequential requests over a single QUIC connection, bypassing concurrent-stream limits and causing unbounded heap growth until the server exhausts memory (denial of service). Fixed in 4.2.18.Final.