Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mfg7-5gfp-c4w3 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final. | |
| Title | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names | |
| Weaknesses | CWE-772 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-13T17:52:58.403Z
Reserved: 2026-08-12T19:00:33.736Z
Link: CVE-2026-73508
No data.
Status : Received
Published: 2026-08-13T15:20:17.463
Modified: 2026-08-13T18:18:17.977
Link: CVE-2026-73508
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:45:03Z
Github GHSA