netty-codec-http2 is vulnerable to Denial of Service (DoS)
53
Medium Risk
A remote client can send an HTTP/2 SETTINGS frame advertising an extremely large header-table size, which DefaultHttp2HeadersEncoder accepts without a cap. The HpackEncoder then retains every unique outbound header indefinitely, degrading header lookups to O(n^2). Throughput collapses as the server generates more unique headers, causing a denial of service. The fix constrains the accepted header-table size.
You are affected if you are using a version that falls within the vulnerable range.
netty-codec-http2 is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 4.1.137.Final and 4.2.0.Final - 4.2.17.Final.
Upgrade the io.netty:netty-codec-http2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.