Uncontrolled Resource Consumption
CVE-2026-100661
Summary
Netty's HTTP/3 codec versions from 4.2.0.Final through 4.2.17.Final contain a Denial-of-Service (DoS) vulnerability in the QPACK prefixed-integer decoder "QpackUtil.decodePrefixedInteger", which does not bound the number of continuation bytes it will process. A remote, unauthenticated peer can open a QPACK unidirectional stream (type 0x02 encoder or 0x03 decoder) and send a first byte with all prefix bits set (e.g. 0xFF for a 7-bit prefix or 0x3F for a 5-bit prefix) followed by an endless run of 0x80 continuation bytes. The decoder returns -1 ('need more bytes'), so callers never consume the input, the "ByteToMessageDecoder cumulator" grows without bound, and each "decode()" invocation re-scans the whole accumulated buffer, yielding O(N^2) CPU cost. The result is unbounded per-connection heap growth "OutOfMemoryError" and event-loop CPU starvation, reachable in every configuration.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- NONE
- HIGH
CWE-400 - Uncontrolled resource consumption
An uncontrolled resource allocation attack (also known as resource exhaustion attack) triggers unauthorized overconsumption of the limited resources in an application, such as memory, file system storage, database connection pool entries, and CPU. This may lead to denial of service for valid users and degradation of the application's functionality as well as that of the host operating system.
Advisory Timeline
- Published