Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33871

32
FAUCET Score

CVE-2026-33871 describes a Denial of Service (DoS) vulnerability affecting Netty HTTP/2 servers in versions prior to 4.1.132.Final and 4.2.10.Final. A remote attacker can exploit this by flooding the server with CONTINUATION frames, leveraging a lack of frame limits and a bypass of existing mitigations, causing excessive CPU usage and rendering the server unresponsive. Rated High severity (CVSS 7.5), this vulnerability has a network attack vector and low attack complexity, requiring no authentication or user interaction. There is currently no evidence of active exploitation, nor are public exploit modules available, despite some community discussion. Organizations using affected Netty versions should upgrade to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.1.132CPE matchmatch criteria
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
>= 4.2.0, < 4.2.10CPE matchmatch criteria
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.13%
Probability of exploitation in next 30 days
EPSS Percentile
63.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0112 is in the 41st percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: io.netty:netty-codec-http2Fixed in: 4.1.132.Final
mavenpatch availablevia ghsa
Product: io.netty:netty-codec-http2Fixed in: 4.2.11.Final
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

mavenGHSA-w9fj-cfpg-grvvhigh

Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass

Mar 26, 2026

References

access.redhat.com / errata/RHSA-2026:10175
access.redhat.com / errata/RHSA-2026:10184
access.redhat.com / errata/RHSA-2026:13571
access.redhat.com / errata/RHSA-2026:14272
access.redhat.com / errata/RHSA-2026:14276
access.redhat.com / errata/RHSA-2026:17668
access.redhat.com / errata/RHSA-2026:17789
access.redhat.com / errata/RHSA-2026:18054
access.redhat.com / errata/RHSA-2026:18055
access.redhat.com / errata/RHSA-2026:18059
access.redhat.com / errata/RHSA-2026:22619
access.redhat.com / errata/RHSA-2026:34608
access.redhat.com / errata/RHSA-2026:7109
access.redhat.com / errata/RHSA-2026:7380
access.redhat.com / errata/RHSA-2026:8159
access.redhat.com / errata/RHSA-2026:8509
access.redhat.com / security/cve/CVE-2026-33871
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-33871.json
github.com / netty/netty/security/advisories/GHSA-w9fj-cfpg-grvv
Vendor Advisory