CyberRota Analysis
AI-GeneratedThe vulnerability affects the `HttpContentEncoder` in Netty versions prior to 4.1.136.Final and 4.2.16.Final, allowing an attacker to exploit HTTP/1.1 pipelining to flood the server with requests, leading to resource exhaustion. This can result in denial of service as the application struggles to process incoming requests due to an unbounded accumulation of data in the `acceptEncodingQueue`. Organizations using affected versions of Netty should prioritize upgrading to the patched versions to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
Related CVEs
Other vulnerabilities affecting the same vendor(s)