What is CVE-2026-56819?
This vulnerability in Netty allows remote unauthenticated peers to leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications with HTTP/2 content enabled. It affects versions 4.1.0.Final through 4.1.135.Final and 4.2.0.Final through 4.2.15.Final. To mitigate, apply relevant patches or disable HTTP/2 content feature.
Azərbaycanca: Bu zəiflik Netty framework-də HTTP/2 protokolu aktiv olan tətbiqlərdə uzaqdan autentifikasiya olunmamış şəxslərə hər `DATA` frame-ə görə bir birbaşa `ByteBuf` yaddaş sahəsini sızdırmasına imkan verir. Təsir Netty-nin 4.1.0.Final-4.1.135.Final və 4.2.0.Final-4.2.15.Final versiyalarına aiddir. Bu problemi aradan qaldırmaq üçün müvafiq yamaları tətbiq etmək və ya HTTP/2 `content` xüsusiyyətini deaktiv etmək lazımdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which Netty versions are affected by CVE-2026-56819?
This vulnerability affects Netty versions 4.1.0.Final through 4.1.135.Final and 4.2.0.Final through 4.2.15.Final.
What measures should be taken to mitigate CVE-2026-56819?
To mitigate this issue, apply relevant patches or disable the HTTP/2 content feature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.