THREAT OPS › Threat News › [GHSA] GHSA-fccg-mwvh-qqg4 (medium) — Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
[GHSA] GHSA-fccg-mwvh-qqg4 (medium) — Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
GHSA-fccg-mwvh-qqg4 Severity: medium CVE: CVE-2026-75596
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
### Summary
Netty's default SNI entrypoint reparses and recopies previously received ClientHello fragments on every additional TLS handshake record. A remote peer can send a small first record that advertises a large ClientHello length
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-75596cve
- https://lzhou1110.github.io/url
- https://zyy0530.github.io/url
- https://str1ckl4nd.github.io/url
- https://maurice.busystar.org/url
- https://7thparkk.github.io/url
Original source: https://github.com/advisories/GHSA-fccg-mwvh-qqg4