Io.netty:netty codec xml: Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion (CVE-2026-73507)
A vulnerability in io.netty.handler.codec.xml.XmlFrameDecoder allows an unauthenticated remote attacker to cause a denial of service via CPU exhaustion by sending specially crafted XML payloads containing repeated '</' sequences. This causes the server's EventLoop thread to repeatedly rescan the buffer, leading to high CPU usage and unresponsiveness. The flaw affects applications using Netty's XmlFrameDecoder component. A patch is available to address this issue.
AI Analysis
Technical Summary
The XmlFrameDecoder in io.netty:netty-codec-xml suffers from a denial of service vulnerability (CVE-2026-73507) due to inefficient handling of XML payloads containing repeated '</' characters. When the decoder encounters '<' followed by '/', it scans for a closing '>' but does not save parser state between decode() calls. An attacker can exploit this by trickle-feeding a payload with repeated '</' sequences, causing the decoder to repeatedly rescan the entire buffer, exhausting CPU resources and hanging the server thread. This vulnerability allows unauthenticated remote attackers to disrupt service by sending malformed XML data to an exposed port.
Potential Impact
The vulnerability results in denial of service through CPU exhaustion, making the affected server's EventLoop thread unresponsive. This impacts availability but does not affect confidentiality or integrity. Any application using Netty's XmlFrameDecoder is vulnerable to remote exploitation without authentication by sending crafted XML payloads.
Mitigation Recommendations
A patch is available to fix this vulnerability. Users of io.netty:netty-codec-xml should apply the official fix as soon as possible. Since this is not a cloud service, remediation depends on updating the affected software component. No vendor advisory content contradicts this; therefore, upgrading to a patched version is recommended.
Io.netty:netty codec xml: Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion (CVE-2026-73507)
Description
A vulnerability in io.netty.handler.codec.xml.XmlFrameDecoder allows an unauthenticated remote attacker to cause a denial of service via CPU exhaustion by sending specially crafted XML payloads containing repeated '</' sequences. This causes the server's EventLoop thread to repeatedly rescan the buffer, leading to high CPU usage and unresponsiveness. The flaw affects applications using Netty's XmlFrameDecoder component. A patch is available to address this issue.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The XmlFrameDecoder in io.netty:netty-codec-xml suffers from a denial of service vulnerability (CVE-2026-73507) due to inefficient handling of XML payloads containing repeated '</' characters. When the decoder encounters '<' followed by '/', it scans for a closing '>' but does not save parser state between decode() calls. An attacker can exploit this by trickle-feeding a payload with repeated '</' sequences, causing the decoder to repeatedly rescan the entire buffer, exhausting CPU resources and hanging the server thread. This vulnerability allows unauthenticated remote attackers to disrupt service by sending malformed XML data to an exposed port.
Potential Impact
The vulnerability results in denial of service through CPU exhaustion, making the affected server's EventLoop thread unresponsive. This impacts availability but does not affect confidentiality or integrity. Any application using Netty's XmlFrameDecoder is vulnerable to remote exploitation without authentication by sending crafted XML payloads.
Mitigation Recommendations
A patch is available to fix this vulnerability. Users of io.netty:netty-codec-xml should apply the official fix as soon as possible. Since this is not a cloud service, remediation depends on updating the affected software component. No vendor advisory content contradicts this; therefore, upgrading to a patched version is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v74w-7mr3-4qg3
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-73507"]
- Ecosystems
- ["Maven"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a7e036ebf8831d5398f92fd
Added to database: 08/13/2026, 17:48:30 UTC
Last enriched: 08/13/2026, 18:09:54 UTC
Last updated: 08/13/2026, 22:05:31 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.