Security Advisory

CVE-2026-59902

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-17 17:48:55
Last updated 2026-08-18 14:50:42
Assigner GitHub_M
CVSS score 7.5
State PUBLISHED

Description

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.