Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
Package
Affected versions
>= 4.2.0.Final, <= 4.2.15.Final
< 4.1.136.Final
Patched versions
4.2.16.Final
4.1.136.Final
Description
Published to the GitHub Advisory Database
Jul 22, 2026
Reviewed
Jul 22, 2026
Last updated
Jul 22, 2026
Impact
HttpContentEncoder(the superclass of the production handlerHttpContentCompressor) maintains a per-channelArrayDeque<CharSequence>namedacceptEncodingQueuethat accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses.References