Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
Published Jun 12, 2026
7.5
HIGHCVSS 3.1
EPSS 0.68%
Description
Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Final and prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked streams, which can cause OOM error. Version 4.2.15.Final patches the issue.
Affected products
-
- Version >= 4.2.0.Final, < 4.2.15.FinalStatusaffectedConstraints-
- Version
No data.
Red Hat build of Apache Camel - HawtIO 4
netty-codec-http3
Under investigation
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Apache Camel - HawtIO 4 | netty-codec-http3 | Under investigation | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-48748 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2488441 Issue Tracking
- https://github.com/advisories/GHSA-4grm-h2qv-h6w6 Advisory
- https://github.com/netty/netty/commit/75127cab731ee35068d1f0667bffa188bc332f5d x_refsource_MISC
- https://github.com/netty/netty/releases/tag/netty-4.2.15.Final x_refsource_MISCRelease Notes
- https://github.com/netty/netty/security/advisories/GHSA-4grm-h2qv-h6w6 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-48748
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48748.json
- https://www.cve.org/CVERecord?id=CVE-2026-48748
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-48748 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2488441 | Issue Tracking | |
| https://github.com/advisories/GHSA-4grm-h2qv-h6w6 | Advisory | |
| https://github.com/netty/netty/commit/75127cab731ee35068d1f0667bffa188bc332f5d | x_refsource_MISC | |
| https://github.com/netty/netty/releases/tag/netty-4.2.15.Final | x_refsource_MISCRelease Notes | |
| https://github.com/netty/netty/security/advisories/GHSA-4grm-h2qv-h6w6 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-48748 | ||
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48748.json | ||
| https://www.cve.org/CVERecord?id=CVE-2026-48748 |
Change history (0)
No recorded changes yet.