CVE-2026-33871 describes a Denial of Service (DoS) vulnerability affecting Netty HTTP/2 servers in versions prior to 4.1.132.Final and 4.2.10.Final. A remote attacker can exploit this by flooding the server with CONTINUATION frames, leveraging a lack of frame limits and a bypass of existing mitigations, causing excessive CPU usage and rendering the server unresponsive. Rated High severity (CVSS 7.5), this vulnerability has a network attack vector and low attack complexity, requiring no authentication or user interaction. There is currently no evidence of active exploitation, nor are public exploit modules available, despite some community discussion. Organizations using affected Netty versions should upgrade to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.132CPE matchmatch criteria | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | ||
>= 4.2.0, < 4.2.10CPE matchmatch criteria | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.