CVE-2026-59901
ADVISORY - githubSummary
The Bzip2Decoder handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [Bzip2BlockDecompressor.read()]
Common Weakness Enumeration (CWE)
ADVISORY - github
Loop with Unreachable Exit Condition ('Infinite Loop')
GitHub
CREATED
UPDATED
ADVISORY IDGHSA-558v-64gr-wgg4
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)