Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
References
| Link | Resource |
|---|---|
| https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-29 18:16
Updated : 2026-08-06 20:29
NVD link : CVE-2026-59901
Mitre link : CVE-2026-59901
CVE.ORG link : CVE-2026-59901
JSON object : View
Products Affected
netty
- netty
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
