SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59899

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The vulnerability affects the `HttpContentEncoder` in Netty versions prior to 4.1.136.Final and 4.2.16.Final, allowing an attacker to exploit HTTP/1.1 pipelining to flood the server with requests, leading to resource exhaustion. This can result in denial of service as the application struggles to process incoming requests due to an unbounded accumulation of data in the `acceptEncodingQueue`. Organizations using affected versions of Netty should prioritize upgrading to the patched versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59899
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.

Related CVEs

Other vulnerabilities affecting the same vendor(s)