Intel

AIKIDO-2025-10209

netty-incubator-codec-classes-quic is vulnerable to Inefficient Algorithmic Complexity

Inefficient Algorithmic ComplexityCVE-2025-29908 Published Apr 7, 2025

57

Medium Risk

This Affects:

JAVAnetty-incubator-codec-classes-quic
0.0.21.Final - 0.0.70.Final
Fixed in 0.0.71.Final
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a hash collision attack in the connection management codec. Remote attackers can trigger a high CPU load on the server —a form of Hash DoS— by initiating multiple connections with specially crafted, colliding Source Connection IDs (SCIDs) that exploit the hash map used for connection tracking.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

netty-incubator-codec-classes-quic is vulnerable to Inefficient Algorithmic Complexity in versions 0.0.21.Final - 0.0.70.Final.

How to fix this

Upgrade the io.netty.incubator:netty-incubator-codec-classes-quic library to the patch version.