{"id":"CVE-2026-75596","aliases":["GHSA-fccg-mwvh-qqg4"],"url":"https://o3.security/vulnerability/CVE-2026-75596","summary":"Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing","details":"### Summary\n\nNetty's default SNI entrypoint reparses and recopies previously received ClientHello fragments on every additional TLS handshake record. A remote peer can send a small first record that advertises a large ClientHello length and then drip the body in many tiny records, causing **superlinear (quadratic) CPU work** before the handshake completes. With 4095 one-byte fragments, the handler recopies **8,386,560 bytes** from only **24,579 bytes** on the wire — a **341× amplification** ratio.\n\n### Affected Entrypoints\n\n- `io.netty.handler.ssl.SniHandler` — default constructors\n- `io.netty.handler.ssl.SslClientHelloHandler` — pre-handshake ClientHello aggregation path\n\n### Vulnerable Code Locations\n\n- `handler/src/main/java/io/netty/handler/ssl/SniHandler.java:85`\n- `handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java:75` (decode entry)\n- `handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java:165` (handshakeBuffer.clear)\n- `handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java:174` (writeBytes re-copy)\n- `codec-base/src/main/java/io/netty/handler/codec/ByteToMessageDecoder.java:294` (cumulation retention)\n\n### Exploit Path\n\n```\n1. TCP connection → SniHandler → SslClientHelloHandler.decode\n2. First record: TLS handshake header declaring large ClientHello length (e.g., 4096 bytes)\n3. Attacker sends thousands of tiny follow-on handshake records (1 byte each)\n4. On each fragment: handshakeBuffer.clear() + writeBytes() re-copies ALL accumulated body bytes\n5. Total bytes copied = n*(n+1)/2 where n = number of body bytes → quadratic\n6. Event-loop CPU exhausted before SslHandler takes over\n```\n\n### Impact\n\n- **Vulnerability Type:** Inefficient Algorithmic Complexity\n- An unauthenticated network attacker can drive disproportionate CPU consumption on the Netty event loop\n- Affects **all** Netty deployments using `SniHandler` for TLS termination (the default SNI path)\n- No privileges, user interaction, or special configuration required\n- Can degrade or stall TLS connection handling for all clients on the affected event loop\n- The attack requires only modest bandwidth (~25 KB) to trigger significant CPU work\n\n---\n### Credits\n\nFound by a security research team from the University of Sydney, focusing on detecting open source software vulnerabilities.\nLiyi Zhou: https://lzhou1110.github.io/\nZiyue Wang: https://zyy0530.github.io/\nStrick: https://str1ckl4nd.github.io/\nMaurice: https://maurice.busystar.org/\nChenchen Yu: https://7thparkk.github.io/","published":"2026-08-19T20:56:21.657Z","modified":"2026-09-30T12:11:47.361591001Z","cvss":null,"epss":{"score":0.00351,"percentile":0.28079,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.netty:netty-handler","fixedVersion":"4.2.17.Final"},{"ecosystem":"Maven","name":"io.netty:netty-handler","fixedVersion":"4.1.137.Final"}],"fix":{"url":"https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","label":"netty/netty@1b5abc6"},"references":[{"type":"WEB","url":"https://github.com/netty/netty/releases/tag/netty-4.1.137.Final"},{"type":"WEB","url":"https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75596.json"},{"type":"ADVISORY","url":"https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75596"},{"type":"FIX","url":"https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7"},{"type":"FIX","url":"https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961"},{"type":"FIX","url":"https://github.com/netty/netty/pull/17213"},{"type":"FIX","url":"https://github.com/netty/netty/pull/17217"},{"type":"PACKAGE","url":"https://github.com/netty/netty"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-30T12:11:47.361591001Z"}}