PatchSiren cyber security CVE debrief
CVE-2026-50560 netty CVE debrief
CVE-2026-50560 is a vulnerability in Netty, a network application framework. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. The vulnerability is caused by the `SETTINGS_MAX_HEADER_LIST_SIZE` setting in the http2 specification. When a client sends this setting to Netty, it can cause Netty to behave in a way that is similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
- Vendor
- netty
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-12
- Original CVE updated
- 2026-06-15
- Advisory published
- 2026-06-12
- Advisory updated
- 2026-06-15
Who should care
Users of Netty prior to versions 4.1.135.Final and 4.2.15.Final should be aware of this vulnerability and take steps to upgrade to a patched version.
Technical summary
The vulnerability is caused by the `SETTINGS_MAX_HEADER_LIST_SIZE` setting in the http2 specification. When a client sends this setting to Netty, it can cause Netty to behave in a way that is similar to the http2 reset attack, but with a different on-the-wire signature.
Defensive priority
MEDIUM
Recommended defensive actions
- Upgrade to Netty version 4.1.135.Final or 4.2.15.Final or later.
- Review and adjust the `SETTINGS_MAX_HEADER_LIST_SIZE` setting in your Netty configuration.
Evidence notes
The CVE-2026-50560 vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-50560) and has a CVSS score of 6.9. More information can be found on [nvd](https://nvd.nist.gov/vuln/detail/CVE-2026-50560).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-50560 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-50560
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-50560 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50560
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/netty/netty/releases/tag/netty-4.1.135.Final
-
Source reference
Unverified legacy reference
URL: https://github.com/netty/netty/releases/tag/netty-4.2.15.Final
-
Source reference
Unverified legacy reference
URL: https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm
-
Source reference
Unverified legacy reference
URL: https://www.rfc-editor.org/rfc/rfc9113.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.