CVE-2026-59902

high

Description

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.

References

https://github.com/netty/netty/security/advisories/GHSA-2qj4-mmr9-4v2f

https://github.com/netty/netty/releases/tag/netty-4.2.17.Final

https://github.com/netty/netty/releases/tag/netty-4.1.137.Final

https://github.com/netty/netty/pull/17217

https://github.com/netty/netty/pull/17213

https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7

Details

Source: Mitre, NVD

Published: 2026-08-17

Updated: 2026-08-18

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High

EPSS

EPSS: 0.00684