CVE-2026-42583 - Netty Lz4FrameDecoder is vulnerable to resource exhaustion

📡 GitHub-Advisory · 2026-05-07

CVE-2026-42583 - Netty Lz4FrameDecoder is vulnerable to resource exhaustion

CVE-2026-42583

GHSA-mj4r-2hfc-f8p6 HIGH maven/io.netty:netty-codec-compression

CVE: CVE-2026-42583

Summary

Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation.

Details

io.netty.handler.codec.compression.Lz4FrameDecoder#decode

Header fields are trusted for sizing. On the compressed path, after readableBytes >= compressedLength, the decoder does ctx.alloc().buffer(decompressedLength, decompressedLength) then decompresses.

PoC

The test below demonstrates how an attacker sending 22 bytes will force the server to allocate 32MB

@Test
    void test() throws Exception {EventLoopGroup workerGroup = new MultiThreadIoEventLoopGroup(NioIoHandler.newFactory());try {AtomicReference<Throwable>serverError = new AtomicReference<>();CountDownLatch latch = new CountDownLatch(1);
ServerBootstrap server = new ServerBootstrap()
                    .group(workerGroup)
                    .channel(NioServerSocketChannel.class)
                    .childHandler(new ChannelInitializer<SocketChannel>() {@Override
                        protected void initChannel(SocketChannel ch) {
ch.pipeline()
                                    .addLast(new Lz4FrameDecoder())
                                    .addLast(new ChannelInboundHandlerAdapter() {@Override
                                        public void exceptionCaught(ChannelHandlerContext ctx,Throwable cause) {if (cause instanceof DecoderException) {serverError.set(cause.getCause());}else {serverError.set(cause);}

📌 来源: GitHub-Advisory | 🆔 CVE-2026-42583 | 📅 2026-05-07

[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)