CVE-2026-48043
MEDIUM 5.3Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
0.6%chance of exploitation in 30 days · 43rd percentile
Impact if exploited
5.3CVSS 3.1 · MEDIUM
- ConfidentialityNone
- IntegrityNone
- AvailabilityLow
What an attacker needs
- ✓Access: Reachable over the network — no local access needed
- ✓Privileges: No account or privileges required
- ✓User interaction: No user interaction needed
- ✓Complexity: No special conditions — reliably repeatable
✓ lowers the bar for an attacker · ⚠ raises it
Affected
Products Netty Red Hat Build Of Apache Camel 3.33 For Quarkus 3.33.2.Sp1 Red Hat Build Of Quarkus 3.27.4.Sp1 Red Hat Build Of Quarkus 3.33.2.Sp1 Cryostat 4 Openshift Serverless Red Hat Amq Broker 7 Red Hat Build Of Apache Camel Hawtio 4
Weakness (CWE)
- CWE-400: Uncontrolled resource consumption
- CWE-401: Memory leak
- CWE-772
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
References
Advisories
Technical & other
- https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j
- https://github.com/netty/netty/releases/tag/netty-4.1.135.Final
- https://github.com/netty/netty/releases/tag/netty-4.2.15.Final
- https://access.redhat.com/security/cve/CVE-2026-48043
- https://bugzilla.redhat.com/show_bug.cgi?id=2488442
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json