Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path… (CVE-2026-75596)
Netty versions prior to 4.1.137.Final and 4.2.17.Final have a vulnerability in the default io.netty.handler.ssl.SniHandler constructors that causes excessive CPU usage during TLS handshake. This occurs because the pre-handshake ClientHello aggregation path inefficiently processes large ClientHello messages delivered in many small TLS records, leading to quadratic CPU work on the event loop. This degrades TLS handling performance for other clients. The issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-75596) affects Netty's io.netty.handler.ssl.SniHandler default constructors prior to versions 4.1.137.Final and 4.2.17.Final. The flaw lies in the pre-handshake ClientHello aggregation path where the handshakeBuffer.clear() and writeBytes() methods recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can exploit this by sending a large ClientHello message fragmented into thousands of tiny TLS records, causing quadratic CPU consumption on the event loop before the TLS handshake completes. This results in degraded TLS handling performance for other clients sharing the event loop. The issue is resolved in the specified fixed versions.
Potential Impact
An unauthenticated remote attacker can cause high CPU usage on the event loop by sending a specially crafted large ClientHello message fragmented into many small TLS records. This leads to degraded TLS handling performance for other clients, potentially causing denial of service conditions due to resource exhaustion. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
Upgrade Netty to version 4.1.137.Final or later, or 4.2.17.Final or later, where this issue is fixed. No other mitigation is required as the fix addresses the root cause of the excessive CPU usage during TLS handshake.
Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path… (CVE-2026-75596)
Description
Netty versions prior to 4.1.137.Final and 4.2.17.Final have a vulnerability in the default io.netty.handler.ssl.SniHandler constructors that causes excessive CPU usage during TLS handshake. This occurs because the pre-handshake ClientHello aggregation path inefficiently processes large ClientHello messages delivered in many small TLS records, leading to quadratic CPU work on the event loop. This degrades TLS handling performance for other clients. The issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
CVSS v3.1
Score 7.5high
Affected software
pkg:deb/ubuntu/netty?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/netty?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/netty?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/netty?arch=source&distro=esm-apps/resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-75596) affects Netty's io.netty.handler.ssl.SniHandler default constructors prior to versions 4.1.137.Final and 4.2.17.Final. The flaw lies in the pre-handshake ClientHello aggregation path where the handshakeBuffer.clear() and writeBytes() methods recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can exploit this by sending a large ClientHello message fragmented into thousands of tiny TLS records, causing quadratic CPU consumption on the event loop before the TLS handshake completes. This results in degraded TLS handling performance for other clients sharing the event loop. The issue is resolved in the specified fixed versions.
Potential Impact
An unauthenticated remote attacker can cause high CPU usage on the event loop by sending a specially crafted large ClientHello message fragmented into many small TLS records. This leads to degraded TLS handling performance for other clients, potentially causing denial of service conditions due to resource exhaustion. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
Upgrade Netty to version 4.1.137.Final or later, or 4.2.17.Final or later, where this issue is fixed. No other mitigation is required as the fix addresses the root cause of the excessive CPU usage during TLS handshake.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-75596
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:Pro:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6ab4be53f7a7c54106f0aa31
Added to database: 09/24/2026, 06:08:19 UTC
Last enriched: 09/24/2026, 06:45:43 UTC
Last updated: 09/24/2026, 06:45:43 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.