Netty published a broad set of security advisories covering 22 vulnerabilities across its networking stack, with impacts ranging from remote denial of service to trust-boundary failures. The issues affect multiple modules and protocols, including HTTP/2, HTTP/3, QUIC, DNS, Redis, SCTP, Unix domain sockets, HAProxy PROXY protocol v2, and TLS handling. Reported consequences include uncontrolled memory allocation, ByteBuf and file descriptor leaks, failure to enforce HTTP/2 stream limits, DNS cache poisoning, improper TLS hostname validation, IPv6 subnet access-control bypass, request smuggling, and QUIC reflection or stateless reset abuse.
One of the most serious flaws, CVE-2026-45416, allows a remote attacker to send as little as nine bytes in a crafted TLS ClientHello and trigger roughly 16 MiB of unpooled direct-memory allocation per connection in Netty's SNI handling path. Because the buffer can remain allocated until the connection closes, repeated connections can exhaust direct memory and disrupt services. The flaw affects Netty 4.1.x before 4.1.135.Final and 4.2.0.Final through 4.2.14.Final, and was fixed in 4.1.135.Final and 4.2.15.Final; the wider advisory set was published through Netty's GitHub security advisories and highlights the risk to Java applications that embed Netty as a dependency.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE-2026-45416 issue affecting Netty's SNI handler was fixed in versions 4.1.135.Final and 4.2.15.Final. The flaw allowed a crafted nine-byte TLS ClientHello to trigger roughly 16 MiB of direct-memory allocation per connection, enabling denial of service through memory exhaustion.
A security bulletin described 22 vulnerabilities affecting Netty components, including remote denial-of-service flaws, DNS cache poisoning, HTTP request smuggling, IPv6 subnet access-control bypass, QUIC abuse cases, and improper TLS hostname validation.
Netty's GitHub security advisories page listed multiple vulnerabilities as published on June 5, 2026, covering issues such as memory exhaustion, ByteBuf leaks, DNS cache poisoning, file descriptor leaks, HTTP/2 stream-limit enforcement failures, and SNI pre-allocation behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcecybersecurity-help.cz
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.