VYPR

Netty

by Red Hat

Source repositories

CVEs (1)

  • CVE-2026-93492MedSep 18, 2026
    risk 0.35cvss 5.3epss 0.00

    A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to increased CPU usage and memory…