LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-48059

netty · netty

Published
CVSS7.5
Severityhigh
WeaknessCWE-401
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exception is thrown, the message fires downstream, the decoder removes itself, and the application releases the `HAProxyMessage` normally. Yet the underlying cumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the channel) remains permanently pinned. Version

References

← Back to the CVE Tracker

Our coverage of CVE-2026-48059

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-48059.