Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2qj4-mmr9-4v2f | Netty: Memory Exhaustion in SctpMessageCompletionHandler |
Mon, 17 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netty
Netty netty |
|
| Vendors & Products |
Netty
Netty netty |
Mon, 17 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final. | |
| Title | Netty: Memory Exhaustion in SctpMessageCompletionHandler | |
| Weaknesses | CWE-400 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T17:48:55.663Z
Reserved: 2026-07-07T16:40:07.984Z
Link: CVE-2026-59902
No data.
Status : Received
Published: 2026-08-17T18:17:36.087
Modified: 2026-08-17T18:17:36.087
Link: CVE-2026-59902
No data.
OpenCVE Enrichment
Updated: 2026-08-17T20:15:06Z
Github GHSA