Impact
A flaw in Netty’s HTTP/2 HpackEncoder allows a remote attacker to send a SETTINGS frame with an excessively large MAX_HEADER_TABLE_SIZE value, causing the encoder to store a vast number of unique headers. This results in a sharp increase in CPU usage and memory consumption, ultimately leading to a denial of service for the affected application instance.
Affected Systems
The vulnerability affects a range of Red Hat products that incorporate Netty, including Red Hat AMQ Broker 7, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, and Red Hat build of Quarkus 3.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote client that can establish an HTTP/2 connection and transmit a SETTINGS frame with an oversized MAX_HEADER_TABLE_SIZE. The attacker would need no special credentials, and the exploit relies on resource exhaustion rather than code execution.
OpenCVE Enrichment