Netty disclosed and fixed CVE-2026-48059, a memory leak in its HAProxy PROXY protocol v2 codec that can let remote clients exhaust server memory by sending syntactically valid headers with nested PP2_TYPE_SSL TLVs at depth two or greater. The flaw leaves the underlying pooled ByteBuf cumulation buffer permanently pinned even though parsing completes successfully and no exception is raised, creating an availability risk rather than a confidentiality or integrity impact.
The issue affects Netty releases before 4.1.135.Final and 4.2.15.Final, and the project published fixes in those versions alongside a GitHub security advisory. Separately, Netty also merged a non-security correction for memoryAddress() handling in wrapped direct ByteBuffer paths when Unsafe is disabled, shipping that consistency fix in 4.2.14.Final and auto-porting it to Netty 5.0, but the HAProxy memory-exhaustion bug is addressed in the later 4.2.15.Final release.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE reference says GitHub published the security advisory associated with CVE-2026-48059. The advisory concerns a Netty HAProxy codec memory leak affecting versions before 4.1.135.Final and 4.2.15.Final.
Netty fixed CVE-2026-48059, a memory leak in HAProxy PROXY protocol v2 nested PP2_TYPE_SSL TLV parsing that can pin pooled ByteBuf buffers and cause memory exhaustion. The fix is available in versions 4.1.135.Final and 4.2.15.Final, but the source does not explicitly anchor the release date.
Netty merged a fix for inconsistent exposure of direct ByteBuffer memory addresses when Unsafe is disabled but platform address access is still available. The synopsis states this pull request was merged into the Netty 4.2 branch on 2026-05-18.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceredirect.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.