Vulnerabilities
- CVSS
- 7.5 High
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Risk score
- 60.0
- Published
- 2025-09-04
- Status
- Analyzed
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.
Coverage 1
threat-intel
Multiple vulnerabilities have been discovered in SAP products, including remote code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities can be exploited to cause significant damage.…
Advisories and references