← العودة للجدول
CVE-2026-44892
CVE-2026-44892 — Netty is a network application framework for development of protocol servers and
📅 2026-06-12
🟠 High 🔥 No NVD DDoS DDoS CVSS 7.5

📋 الوصف الكامل

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum header size limit. When a peer does not explicitly specify `HTTP3_SETTINGS_MAX_FIELD_SECTION_SIZE`, the implementation defaults to an unbounded limit. This insecure defa

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

DDoS

🔗 CVE ID

CVE-2026-44892

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v4.2.15

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←