CVE-2026-59901: Netty

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.

Affected products

  • Netty Netty: before 4.1.136 (fixed in 4.1.136); from 4.2.0, before 4.2.16 (fixed in 4.2.16)

Published 2026-07-29. Last modified 2026-08-06.