GHSA-c2gf-v879-257j
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
Quick fix
GHSA-c2gf-v879-257j — io.netty:netty-codec-http2: upgrade to the fixed version with the command below.
# pom.xml: bump <version>4.1.135.Final</version> for io.netty:netty-codec-http2Details
### Impact
The `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it.
A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 4.1.135.Final# pom.xml: bump <version>4.1.135.Final</version> for io.netty:netty-codec-http24.2.0.Alpha1Fixed in: 4.2.15.Final# pom.xml: bump <version>4.2.15.Final</version> for io.netty:netty-codec-http2References
- https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-48043[ADVISORY]
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json[WEB]
- https://github.com/netty/netty/releases/tag/netty-4.2.15.Final[WEB]
- https://github.com/netty/netty/releases/tag/netty-4.1.135.Final[WEB]
- https://github.com/netty/netty[PACKAGE]
- https://bugzilla.redhat.com/show_bug.cgi?id=2488442[WEB]
- https://access.redhat.com/security/cve/CVE-2026-48043[WEB]
- https://access.redhat.com/errata/RHSA-2026:66488[WEB]
- https://access.redhat.com/errata/RHSA-2026:65126[WEB]
- https://access.redhat.com/errata/RHSA-2026:54435[WEB]
- https://access.redhat.com/errata/RHSA-2026:53806[WEB]
- https://access.redhat.com/errata/RHSA-2026:53646[WEB]
- https://access.redhat.com/errata/RHSA-2026:53645[WEB]
- https://access.redhat.com/errata/RHSA-2026:53644[WEB]
- https://access.redhat.com/errata/RHSA-2026:50085[WEB]
- https://access.redhat.com/errata/RHSA-2026:48151[WEB]
- https://access.redhat.com/errata/RHSA-2026:48124[WEB]
- https://access.redhat.com/errata/RHSA-2026:41951[WEB]
- https://access.redhat.com/errata/RHSA-2026:37390[WEB]
- https://access.redhat.com/errata/RHSA-2026:36820[WEB]
- https://access.redhat.com/errata/RHSA-2026:34608[WEB]
- https://access.redhat.com/errata/RHSA-2026:26586[WEB]
- https://access.redhat.com/errata/RHSA-2026:26018[WEB]
- https://access.redhat.com/errata/RHSA-2026:26017[WEB]