Résumé
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
Détails de l’avis
The Bzip2Decoder handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [Bzip2BlockDecompressor.read()]
Références
Vulnérabilités liées
Tout Supply chain →- HIGHCVE-2026-61556
LiquidJS has an infinite loop vulnerability in its `strip_html` filter
- MEDIUMCVE-2026-84309
pypdf: Possible infinite loop for TreeObject.insert_child
- HIGHCVE-2026-54623
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
- HIGHCVE-2026-63202
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
- HIGHCVE-2026-63124
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
- MEDIUMCVE-2026-71436
Mermaid XY Charts are vulnerable to an infinite loop DoS