CVE-2026-93491

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.

Published
September 18, 2026 1:18 PM
Last Modified
September 18, 2026 1:18 PM
Source
[email protected]

Weaknesses (CWE)

CWE-770

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.