Signal is active with 1 mentions in latest observed window
Immediate actions
Patch netty netty systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
Eclipse Vert.x 5.0.9 / 4.5.26 have been released, fixing bugs as well as CVE-2026-33871 and CVE-2026-33870 : https://vertx.io/blog/eclipse-vert-x-5-0-9/
and https://vertx.io/blog/eclipse-vert-x-4-5-26/
Post summary
Eclipse Vert.x 5.0.9 and 4.5.26 have been released, with updates that fix CVE‑2026‑33871 and CVE‑2026‑33870. Users are encouraged to upgrade to apply these patches.
Atlassian Bamboo has two newly disclosed vulnerabilities—CVE‑2026‑21571 allows OS command injection and CVE‑2026‑33871 can cause service disruption via HTTP/2 overload—both of which have been fixed by the vendor. No active exploitation or PoC is reported, but technical details and the patch notice are highlighted.
CVE-2026-33871 Netty is an asynchronous, event-driven network application framework. In versions prior to http://4.1.132.Final and http://4.2.10.Final, a remote user can trigger a Denial of Servi… https://www.cve.org/CVERecord?id=CVE-2026-33871
Post summary
CVE‑2026‑33871 is a Denial of Service vulnerability in Netty affecting versions older than 4.1.132 and 4.2.10; upgrading to those versions mitigates the issue.