Security Digest: July 30, 2026 - 1 Critical Vulnerability

One high-severity flaw in Netty can be triggered remotely to exhaust direct memory and crash services. The issue affects widely used Netty releases in the 4.1 and 4.2 lines and should be treated as an immediate patch priority for any application or platform that processes PROXY protocol traffic.

· 41 min read

Executive Summary

One high-severity flaw in Netty can be triggered remotely to exhaust direct memory and crash services. The issue affects widely used Netty releases in the 4.1 and 4.2 lines and should be treated as an immediate patch priority for any application or platform that processes PROXY protocol traffic. If you use Netty’s codec-haproxy module, upgrade now and verify that exposed services are not accepting untrusted PROXY protocol input.

Critical Vulnerabilities

CVE-2026-55851: Netty HAProxyMessageDecoder memory exhaustion vulnerability

  • Impact: Attackers can send crafted PROXY protocol v2 traffic that causes Netty to keep accumulating inbound data until direct memory is exhausted, leading to service degradation, crashes, or denial of service.
  • Affected Systems: Netty 4.2.0.Final through 4.2.15.x and 4.1.0.Final through 4.1.135, specifically the codec-haproxy module’s HAProxyMessageDecoder.
  • Immediate Action: Upgrade immediately to 4.2.16.Final or 4.1.136.Final. If you cannot patch right away, disable or restrict PROXY protocol handling at the edge and block untrusted sources from reaching the affected listener.
  • Mitigation: Apply the fixed Netty release, then confirm no service is still running an affected dependency version in application bundles, containers, or shaded JARs. Where patching is delayed, place the service behind trusted load balancers only and remove any public exposure to PROXY protocol parsing.

Previously Alerted

What to Do Now

  1. Patch Netty immediately to 4.1.136.Final or 4.2.16.Final across all services, images, and dependency bundles.
  2. Identify exposed listeners that accept PROXY protocol traffic and restrict them to trusted load balancers or internal networks only.
  3. Check for embedded copies of Netty in shaded JARs, vendor appliances, serverless packages, and container images.
  4. Restart affected services after upgrade to clear any memory pressure and confirm the new version is active.
  5. Monitor for abnormal direct memory growth, repeated restarts, and connection spikes on any service using codec-haproxy.

Verification: confirm the deployed Netty version in build manifests and runtime logs, then test that the affected service no longer loads a vulnerable codec-haproxy release.

Monitoring: watch for sudden increases in direct memory usage, out-of-memory events, and unusual PROXY protocol connections from untrusted sources. Alert on any service that begins recycling under light traffic.

Related Resources

  • Internal blog post on dependency exposure and emergency upgrade workflows — coming soon.
  • Internal blog post on container image scanning for embedded vulnerable libraries — coming soon.
  • Official Netty release notes and security advisory for 4.1.136.Final and 4.2.16.Final.

Keep reading