Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
This issue has been addressed in the following products: Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 Via RHSA-2026:8159 https://access.redhat.com/errata/RHSA-2026:8159
This issue has been addressed in the following products: Red Hat AMQ Broker 7.14.0 Via RHSA-2026:8509 https://access.redhat.com/errata/RHSA-2026:8509
This issue has been addressed in the following products: Streams for Apache Kafka 3.2.0 Via RHSA-2026:13571 https://access.redhat.com/errata/RHSA-2026:13571
This issue has been addressed in the following products: Red Hat AMQ Broker 7.13.5 Via RHSA-2026:14272 https://access.redhat.com/errata/RHSA-2026:14272
This issue has been addressed in the following products: Red Hat AMQ Broker 7.12.7 Via RHSA-2026:14276 https://access.redhat.com/errata/RHSA-2026:14276
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 Via RHSA-2026:17668 https://access.redhat.com/errata/RHSA-2026:17668
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 Via RHSA-2026:18059 https://access.redhat.com/errata/RHSA-2026:18059
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 Via RHSA-2026:18055 https://access.redhat.com/errata/RHSA-2026:18055
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 Via RHSA-2026:18054 https://access.redhat.com/errata/RHSA-2026:18054