Impact
A flaw in Netty’s HTTP/2 HpackEncoder allows a remote attacker to send a SETTINGS frame with an oversized MAX_HEADER_TABLE_SIZE. This causes the encoder to store an enormous number of unique headers, which in turn drives CPU usage and swells memory consumption until the application becomes unresponsive. The result is a denial of service that can be triggered purely by sending HTTP/2 traffic; no code execution or privilege escalation is required. The vulnerability exemplifies a classic resource exhaustion weakness (CWE‑1035).
Affected Systems
The issue surfaces in Netty components that are embedded within a variety of Red Hat products. Affected offerings include Red Hat AMQ Broker 7, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, and Red Hat build of Debezium 3. The data does not provide specific fixed or affected versions, so any installation that incorporates this version of Netty is potentially vulnerable.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. EPSS is listed as < 1 %, and the vulnerability is not in the CISA KEV catalog. Exploitation requires only an HTTP/2 connection from a remote client and the ability to send a SETTINGS frame with an excessively large MAX_HEADER_TABLE_SIZE. No authentication or privileged access is necessary; the attack leverages resource exhaustion rather than code execution.
OpenCVE Enrichment