A flaw was found in Netty's HttpServerCodec. (CVE-2026-93491)
A denial of service vulnerability exists in Netty's HttpServerCodec component. An unauthenticated remote attacker can exploit this by sending pipelined HTTP/1.1 requests on a single connection and withholding reads, causing an unbounded queue growth that leads to excessive heap memory consumption and service disruption. This flaw affects multiple specific versions of Netty. No official fix or mitigation meeting Red Hat's criteria is currently available.
AI Analysis
Technical Summary
CVE-2026-93491 is a denial of service vulnerability in Netty's HttpServerCodec. The vulnerability arises when an attacker pipelines HTTP/1.1 requests on a single connection and withholds reading responses, causing the methodOverflowQueue to grow without limit. This unbounded queue growth leads to unbounded heap memory consumption, resulting in memory exhaustion and denial of service. The issue affects multiple specific Netty versions as listed. Red Hat's advisory confirms the absence of an effective mitigation or fix that meets their criteria at this time.
Potential Impact
Exploitation of this vulnerability allows a remote, unauthenticated attacker to cause unbounded memory consumption on affected systems, leading to denial of service due to memory exhaustion. There is no impact on confidentiality or integrity, but availability is significantly affected.
Mitigation Recommendations
Currently, no mitigation or official fix meeting Red Hat's criteria for ease of use, deployment, applicability, or stability is available. Users are advised to monitor vendor advisories for updates and consider upgrading to fixed versions when they become available. Applying mitigations or workarounds is not currently feasible per Red Hat's assessment.
A flaw was found in Netty's HttpServerCodec. (CVE-2026-93491)
Description
A denial of service vulnerability exists in Netty's HttpServerCodec component. An unauthenticated remote attacker can exploit this by sending pipelined HTTP/1.1 requests on a single connection and withholding reads, causing an unbounded queue growth that leads to excessive heap memory consumption and service disruption. This flaw affects multiple specific versions of Netty. No official fix or mitigation meeting Red Hat's criteria is currently available.
CVSS v3.1
Score 7.5high
Affected software
pkg:deb/ubuntu/netty?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/netty?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/netty?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/netty?arch=source&distro=esm-apps/resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93491 is a denial of service vulnerability in Netty's HttpServerCodec. The vulnerability arises when an attacker pipelines HTTP/1.1 requests on a single connection and withholds reading responses, causing the methodOverflowQueue to grow without limit. This unbounded queue growth leads to unbounded heap memory consumption, resulting in memory exhaustion and denial of service. The issue affects multiple specific Netty versions as listed. Red Hat's advisory confirms the absence of an effective mitigation or fix that meets their criteria at this time.
Potential Impact
Exploitation of this vulnerability allows a remote, unauthenticated attacker to cause unbounded memory consumption on affected systems, leading to denial of service due to memory exhaustion. There is no impact on confidentiality or integrity, but availability is significantly affected.
Mitigation Recommendations
Currently, no mitigation or official fix meeting Red Hat's criteria for ease of use, deployment, applicability, or stability is available. Users are advised to monitor vendor advisories for updates and consider upgrading to fixed versions when they become available. Applying mitigations or workarounds is not currently feasible per Red Hat's assessment.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-93491
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:Pro:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be2ef7a7c54106eeec2b
Added to database: 09/24/2026, 06:07:42 UTC
Last enriched: 09/24/2026, 06:31:00 UTC
Last updated: 09/25/2026, 04:47:33 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.