Threat Advisory

Netty Flaws Enable CORS Handler Alteration and Service Memory Overuse

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Netty transport with SctpMessageCompletionHandler, allowing an unauthenticated attacker to cause an OutOfMemoryError by sending large SCTP fragments. These vulnerabilities present a significant risk to applications using Netty's SCTP transport with SctpMessageCompletionHandler.

CVE-2026-59902 (CVSS 7.5 — High): A vulnerability in Netty’s SctpMessageCompletionHandler allows unauthenticated attackers to trigger memory exhaustion and cause an OutOfMemoryError by sending large SCTP fragments due to insufficient limits on buffered fragment sizes.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Netty transport with SctpMessageCompletionHandler, allowing an unauthenticated attacker to cause an OutOfMemoryError by sending large SCTP fragments. These vulnerabilities present a significant risk to applications using Netty's SCTP transport with SctpMessageCompletionHandler.

CVE-2026-59902 (CVSS 7.5 — High): A vulnerability in Netty’s SctpMessageCompletionHandler allows unauthenticated attackers to trigger memory exhaustion and cause an OutOfMemoryError by sending large SCTP fragments due to insufficient limits on buffered fragment sizes.[emaillocker id="1283"]

CVE-2026-59903 (CVSS 6.5 — Medium): A vulnerability in Netty’s CorsHandler allows cache poisoning and sensitive information disclosure by overwriting existing Vary headers, causing caching systems to serve user-specific responses to unauthorized users.

RECOMMENDATIONS:

  • We recommend you to update io.netty:netty-transport-sctp and io.netty:netty-codec-http to below version:
  • CVE-2026-59902: https://github.com/advisories/GHSA-2qj4-mmr9-4v2f
  • CVE-2026-59903: https://github.com/advisories/GHSA-8c42-7qj2-3j46

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu