Report: Latest: CVE-2026-42582 - Netty: HTTP/3 QPACK literal unbounded allocation

Report: Latest: CVE-2026-42582 - Netty: HTTP/3 QPACK literal unbounded allocation

CVE ID :CVE-2026-42582 Published : May 13, 2026, 7:17 p.m. | 29 minutes ago Description :Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <=Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
May 13, 2026
Attack Vector: network