Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: SpdySessionHandler defaults localConcurrentStreams to Integer.MAX_VALUE and exposes no API to change it. A remote peer that opens a SPDY connection and sends millions of SYN_STREAM frames with FLAG_FIN=0 causes the server to allocate unbounded heap and direct memory, eventually triggering a JVM OutOfMemoryError and crashing the service. Fixed in 4.1.138.Final and 4.2.18.Final.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-100655 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
This CVE ID has been rejected as a duplicate.
CVE-2026-100655
- High severity, but no confirmed exploitation yet
A fix is available — apply it.
- CVSS v3
- 7.5
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- 0.2%
- EPSS %ILE
- 14th
- KEV
- Not listed
Published
September 26, 2026
Last Modified
September 28, 2026
Advisory Details (2)
Auto-updated Sep 26, 2026Netty before 4.1.138.Final Denial of Service via SpdySessionHandler | Advisories | VulnCheck
https://www.vulncheck.com/advisories/netty-before-4.1.138-final-denial-of-service-via-spdysessionhandlerSpdySessionHandler accepts an unlimited number of concurrent remote-initiated · Advisory · netty/netty · GitHub
https://github.com/netty/netty/security/advisories/GHSA-rmcw-9fcq-wjq7Vendor Advisories for CVE-2026-100655(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Affected Packages
(3 across 3 ecosystems)
Debian:12(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| netty | 1:4.1.48-10 ... 1:4.1.48-9 (12 versions) |
| — |
Debian:13(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| netty | 1:4.1.48-10 ... 1:4.1.48-16 (8 versions) |
| — |
Debian:14(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| netty | 1:4.1.48-10 ... 1:4.1.48-16 (7 versions) |
| — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 10× in last 7d / 21× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-10-02 08:31 UTCGHSA enrichment
- 2026-09-29 06:33 UTCEG score recompute▼ 7.50
- 2026-09-29 06:33 UTCGHSA enrichment
- 2026-09-28 19:30 UTCEG score recompute
- 2026-09-28 19:29 UTCGHSA enrichment
- 2026-09-28 18:37 UTCEG score recompute
- 2026-09-28 18:37 UTCGHSA enrichment
- 2026-09-28 15:30 UTCEG score recompute
- 2026-09-28 15:30 UTCGHSA enrichment
- 2026-09-28 13:50 UTCEPSS rescore
- 2026-09-28 04:26 UTCGHSA enrichment
- 2026-09-27 17:24 UTCEG score recompute
- 2026-09-27 17:24 UTCGHSA enrichment
- 2026-09-27 16:36 UTCEG score recompute
- 2026-09-27 16:36 UTCGHSA enrichment
- 2026-09-27 12:40 UTCGHSA enrichment
- 2026-09-27 01:38 UTCEG score recompute
- 2026-09-27 01:37 UTCGHSA enrichment
- 2026-09-26 14:33 UTCEG score recompute
- 2026-09-26 13:38 UTCEG score recompute
- 2026-09-26 13:30 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Frequently asked(5)
What is CVE-2026-100655?
When was CVE-2026-100655 disclosed?
Is CVE-2026-100655 actively exploited?
What is the CVSS score of CVE-2026-100655?
How do I remediate CVE-2026-100655?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-100655
Is Your Infrastructure Affected by CVE-2026-100655?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.