CVE-2026-59902
Last modified
CVE-2026-59902 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netty | Netty | < 4.1.137 |
| Netty | Netty | >= 4.2.0, < 4.2.17 |
References
- https://github.com/netty/netty/pull/17213Issue Tracking, Patch
- https://github.com/netty/netty/pull/17217Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-59902?
How severe is CVE-2026-59902?
How do I fix CVE-2026-59902?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59897Hono is a Web application framework that provides support fo…5.3
- CVE-2026-59898Netty is an asynchronous, event-driven network application f…7.5
- CVE-2026-59899Netty is an asynchronous, event-driven network application f…7.5
- CVE-2026-5990A vulnerability has been found in Tenda F451 1.0.0.7. Affect…8.8
- CVE-2026-59900Netty is an asynchronous, event-driven network application f…5.3
- CVE-2026-59901Netty is an asynchronous, event-driven network application f…7.5
- CVE-2026-59903Netty is an asynchronous, event-driven network application f…7.5
- CVE-2026-59909Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Pa…7.1
- CVE-2026-5991A vulnerability was found in Tenda F451 1.0.0.7. Affected by…8.8
- CVE-2026-59910Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an I…7.8
- CVE-2026-59911Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an I…5.5
- CVE-2026-59912Dell Display and Peripheral Manager (DDPM Mac), versions pri…7.8
Are you affected by CVE-2026-59902?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
