Medium severity5.3OSV Advisory· Published Mar 31, 2025· Updated Apr 15, 2026
CVE-2025-29908
CVE-2025-29908
Description
Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash collision vulnerability (in the hash map used to manage connections) allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This vulnerability is fixed in 0.0.71.Final.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.netty.incubator:netty-incubator-codec-quicMaven | < 0.0.71.Final | 0.0.71.Final |
Affected products
2- Range: netty-incubator-codec-parent-quic-0.0.21.Final, netty-incubator-codec-parent-quic-0.0.22.Final, netty-incubator-codec-parent-quic-0.0.23.Final, …
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.