Two high-severity denial-of-service vulnerabilities were disclosed in widely used Java infrastructure components, allowing remote attackers to exhaust CPU and memory and disrupt application availability without authentication. In Micronaut, CVE-2026-33013 affects versions before 4.10.16 and 3.10.5 and is caused by improper handling of descending array indices during application/x-www-form-urlencoded body binding in JsonBeanPropertyBinder::expandArrayToThreshold. A crafted request using indexed parameters such as authors[1].name followed by authors[0].name can trigger a non-terminating loop, CPU exhaustion, and an OutOfMemoryError.
Netty separately patched CVE-2026-33871, a denial-of-service flaw in HTTP/2 processing that affects versions before 4.1.132.Final and 4.2.10.Final. The bug lets attackers flood servers with CONTINUATION frames because the framework did not enforce a limit on their number, and existing size-based protections could be bypassed with zero-byte frames. The result is excessive CPU consumption with minimal bandwidth, potentially leaving HTTP/2 services unresponsive. The issues are tracked as CWE-835 in Micronaut and CWE-770 in Netty, and both vendors released fixed versions for affected branches.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Netty fixed the HTTP/2 CONTINUATION frame flood vulnerability in versions 4.1.132.Final and 4.2.10.Final. The update closed the zero-byte frame bypass and addressed the lack of limits that enabled remote DoS.
A new CVE was published for Netty describing a denial-of-service issue in HTTP/2 servers caused by unlimited CONTINUATION frames and a zero-byte frame bypass of size-based mitigations. The flaw affected versions prior to 4.1.132.Final and 4.2.10.Final and could drive high CPU usage with minimal bandwidth.
Micronaut addressed CVE-2026-33013 in versions 4.10.16 and 3.10.5. The fix remediated incorrect handling in JsonBeanPropertyBinder::expandArrayToThreshold that allowed remote DoS via crafted indexed form parameters.
A denial-of-service flaw in Micronaut's form-urlencoded body binding was received by security-advisories@github.com. The bug involved descending array indices causing a non-terminating loop, CPU exhaustion, and possible OutOfMemoryError.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.