VYPR
High severity7.5OSV Advisory· Published Jul 21, 2026· Updated Aug 7, 2026

CVE-2026-56816

CVE-2026-56816

Description

Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's Http3FrameCodec buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; decodeFrame trusts payLoadLength, allowing an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths to cause memory exhaustion and denial of service. This issue is fixed in version 4.2.16.Final.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.netty:netty-codec-http3Maven
< 4.2.16.Final4.2.16.Final

Affected products

37

Patches

Vulnerability mechanics

References

5

News mentions

1