CVE-2026-33871Patch(netty / netty)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch netty netty systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netty

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Peaked 2d ago at 1 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
netty

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-28: 1Mentions · 2026-04-29: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-03-28: 1Technical Details · 2026-04-29: 103-2503-2804-29
Signal classification1 categories
Patch
3100.0%
Referenced assets6 URLs
Full discourse3 posts
  • Eclipse Vert.x@vertx_project
    Patch

    Eclipse Vert.x 5.0.9 / 4.5.26 have been released, fixing bugs as well as CVE-2026-33871 and CVE-2026-33870 : https://vertx.io/blog/eclipse-vert-x-5-0-9/ and https://vertx.io/blog/eclipse-vert-x-4-5-26/

    Post summary

    Eclipse Vert.x 5.0.9 and 4.5.26 have been released, with updates that fix CVE‑2026‑33871 and CVE‑2026‑33870. Users are encouraged to upgrade to apply these patches.

    21080316
    4.4K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Atlassian Bamboo の脆弱性 CVE-2026-21571/33871  が FIX:リモート・コマンド・インジェクションの恐れ https://iototsecnews.jp/2026/04/22/critical-atlassian-bamboo-data-center-and-server-flaw-enables-command-injection-attacks/ Atlassian Bamboo に、二つの脆弱性が発見されました。一つ目の CVE-2026-21571 は、外部からの入力を適切に処理できず、サーバを操作する命令が実行されてしまう、OS コマンド・インジェクションに起因します。これにより、意図しない操作を許してしまいます。二つ目の CVE-2026-33871 は、製品に組み込まれた外部ライブラリの HTTP/2 処理に問題があり、過度な負荷がかかることで、サービスが止まってしまう恐れがあります。ご利用のチームは、ご注意ください。 #Atlassian #BambooDataCenter #CVE202621571 #CVE202633871 #Vulnerability

    Post summary

    Atlassian Bamboo has two newly disclosed vulnerabilities—CVE‑2026‑21571 allows OS command injection and CVE‑2026‑33871 can cause service disruption via HTTP/2 overload—both of which have been fixed by the vendor. No active exploitation or PoC is reported, but technical details and the patch notice are highlighted.

    01000122
    485 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33871 Netty is an asynchronous, event-driven network application framework. In versions prior to http://4.1.132.Final and http://4.2.10.Final, a remote user can trigger a Denial of Servi… https://www.cve.org/CVERecord?id=CVE-2026-33871

    Post summary

    CVE‑2026‑33871 is a Denial of Service vulnerability in Netty affecting versions older than 4.1.132 and 4.2.10; upgrading to those versions mitigates the issue.

    00000123
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnettynetty---

Explore more