What is CVE-2026-59902?
CVE-2026-59902 is a vulnerability in Netty's 'SctpMessageCompletionHandler' component. Due to missing checks on 'maxBufferedBytes', an unauthenticated remote peer can exhaust memory by sending large messages, leading to a Denial of Service (DoS). Upgrade to Netty 4.1.137.Final or 4.2.17.Final to mitigate the issue.
Azərbaycanca: CVE-2026-59902 Netty çərçivəsində 'SctpMessageCompletionHandler' komponentində aşkar edilmiş boşluqdur. Bu qüsur autentifikasiya olunmamış uzaq hücumçuya 'maxBufferedBytes' limiti nəzərdə tutulmadığı üçün yaddaşı tükəndirərək xidmət rəddi (DoS) yaratmağa imkan verir. Netty 4.1.137.Final və 4.2.17.Final versiyalarına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What component in Netty is affected by CVE-2026-59902?
CVE-2026-59902 is found in the 'SctpMessageCompletionHandler' component of the Netty framework.
What are the recommended Netty versions to mitigate CVE-2026-59902?
To mitigate this vulnerability, you should upgrade to Netty 4.1.137.Final or 4.2.17.Final.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.