CVE-2026-93558

A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consuming excessive memory. Eventually, this can cause the Java Virtual Machine (JVM) to exhaust its heap, resulting in a Denial of Service (DoS) for the affected server.

  • Published Sep 18, 2026
  • CVSS 7.5 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-93558 at the National Vulnerability Database