THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-93wv-jw9v-4972 (high) — Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

[GHSA] GHSA-93wv-jw9v-4972 (high) — Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

medgithub_advisoriesPublished 2026-07-31

GHSA-93wv-jw9v-4972 Severity: high CVE: CVE-2026-56819

Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

### Summary

A remote, unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-93wv-jw9v-4972