THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2qj4-mmr9-4v2f (high) — Netty: Memory Exhaustion in SctpMessageCompletionHandler

[GHSA] GHSA-2qj4-mmr9-4v2f (high) — Netty: Memory Exhaustion in SctpMessageCompletionHandler

medgithub_advisoriesPublished 2026-08-17

GHSA-2qj4-mmr9-4v2f Severity: high CVE: CVE-2026-59902

Netty: Memory Exhaustion in SctpMessageCompletionHandler

### Summary SctpMessageCompletionHandler does not limit the total size of buffered fragments, allowing an unauthenticated attacker to cause an OutOfMemoryError by sending large SCTP fragments.

### Details `io.netty.handler.codec.sctp.SctpMessageCompletionHandler` buffers fragments for

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2qj4-mmr9-4v2f