What is CVE-2026-59901?
This vulnerability in Netty's Bzip2Decoder handler allows a denial-of-service attack via a crafted Bzip2 stream that permanently captures the event-loop. Versions prior to 4.1.136.Final and 4.2.16.Final are affected, and applying the update is recommended.
Azərbaycanca: Bu zəiflik Netty framework-də Bzip2Decoder handler-də aşkarlanıb və xüsusi hazırlanmış Bzip2 axını vasitəsilə event-loop-u daimi ələ keçirərək denial-of-service hücumuna imkan verir. 4.1.136.Final və 4.2.16.Final versiyalarından əvvəlki versiyalar təsirlənir, yeniləmə tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which Netty component was CVE-2026-59901 discovered?
This vulnerability was discovered in the Bzip2Decoder handler in the Netty framework.
What action is recommended to address the affected versions for CVE-2026-59901?
Since versions prior to 4.1.136.Final and 4.2.16.Final are affected, applying the update is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.