GHSA-mm9x-g8pc-w292
HIGHCVE-2020-11612The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
- Affected
- >= 4.1.0, < 4.1.46
- Fixed in
- 4.1.46
- Published
- 2020-06-15
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference