THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-42587 (HIGH 7.5) — Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for

[NVD] CVE-2026-42587 (HIGH 7.5) — Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for

lownvdPublished 2026-05-13

CVE-2026-42587 CVSS: 7.5 HIGH Published: 2026-05-13T19:17:24.460

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is si

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-42587