Multiple vulnerabilities have been identified in Netty transport with SctpMessageCompletionHandler, allowing an unauthenticated attacker to cause an OutOfMemoryError by sending large SCTP fragments. These vulnerabilities present a significant risk to applications using Netty's SCTP transport with SctpMessageCompletionHandler.
CVE-2026-59902 (CVSS 7.5 — High): A vulnerability in Netty’s SctpMessageCompletionHandler allows unauthenticated attackers to trigger memory exhaustion and cause an OutOfMemoryError by sending large SCTP fragments due to insufficient limits on buffered fragment sizes.[/subscribe_to_unlock_form]
Multiple vulnerabilities have been identified in Netty transport with SctpMessageCompletionHandler, allowing an unauthenticated attacker to cause an OutOfMemoryError by sending large SCTP fragments. These vulnerabilities present a significant risk to applications using Netty's SCTP transport with SctpMessageCompletionHandler.
CVE-2026-59902 (CVSS 7.5 — High): A vulnerability in Netty’s SctpMessageCompletionHandler allows unauthenticated attackers to trigger memory exhaustion and cause an OutOfMemoryError by sending large SCTP fragments due to insufficient limits on buffered fragment sizes.[emaillocker id="1283"]
CVE-2026-59903 (CVSS 6.5 — Medium): A vulnerability in Netty’s CorsHandler allows cache poisoning and sensitive information disclosure by overwriting existing Vary headers, causing caching systems to serve user-specific responses to unauthorized users.
The following reports contain further technical details:
[/emaillocker]