THREAT OPS › Threat News › [GHSA] GHSA-2qj4-mmr9-4v2f (high) — Netty: Memory Exhaustion in SctpMessageCompletionHandler
[GHSA] GHSA-2qj4-mmr9-4v2f (high) — Netty: Memory Exhaustion in SctpMessageCompletionHandler
GHSA-2qj4-mmr9-4v2f Severity: high CVE: CVE-2026-59902
Netty: Memory Exhaustion in SctpMessageCompletionHandler
### Summary SctpMessageCompletionHandler does not limit the total size of buffered fragments, allowing an unauthenticated attacker to cause an OutOfMemoryError by sending large SCTP fragments.
### Details `io.netty.handler.codec.sctp.SctpMessageCompletionHandler` buffers fragments for
Indicators of compromise
- CVE-2026-59902cve
- CVE-2026-46340cve
Original source: https://github.com/advisories/GHSA-2qj4-mmr9-4v2f