Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-59901

5 дней назад

(Netty is an asynchronous, event-driven network application framework. ...)

EPSS: Низкий
redhat логотип

CVE-2026-59901

26 дней назад

A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data can trigger an infinite loop, causing the decoder thread to consume excessive CPU resources. This leads to a denial of service (DoS), requiring manual intervention to restore service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-59901

5 дней назад

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.

EPSS: Низкий
debian логотип

CVE-2026-59901

5 дней назад

Netty is an asynchronous, event-driven network application framework. ...

EPSS: Низкий
github логотип

GHSA-558v-64gr-wgg4

12 дней назад

Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-59901

(Netty is an asynchronous, event-driven network application framework. ...)

0%
Низкий
5 дней назад
redhat логотип
CVE-2026-59901

A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data can trigger an infinite loop, causing the decoder thread to consume excessive CPU resources. This leads to a denial of service (DoS), requiring manual intervention to restore service.

CVSS3: 7.5
0%
Низкий
26 дней назад
nvd логотип
CVE-2026-59901

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.

0%
Низкий
5 дней назад
debian логотип
CVE-2026-59901

Netty is an asynchronous, event-driven network application framework. ...

0%
Низкий
5 дней назад
github логотип
GHSA-558v-64gr-wgg4

Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

0%
Низкий
12 дней назад

Уязвимостей на страницу