Feed/CVE-2026-59901
CVE-2026-59901HIGHCVSS 7.5

Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

Published Jul 22, 2026·Updated Aug 6, 2026

NVD Description

The `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]

Affected Packages (2)

io.netty:netty-codecMAVEN
Fixed in 4.1.136.Final
io.netty:netty-codec-compressionMAVEN
From 4.2.0.Final
Fixed in 4.2.16.Final

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free