Overview
About vulnerability
Summary
Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has already exceeded maxHeaderSize and marked the frame truncated. At commit b2d2137c4404af425bf9d5d601a62576f5c06925, a 12,253-byte compressed SPDY header block can declare and inflate a 12 MiB header-name field with maxHeaderSize=16, forcing compression-amplified decode and skip work in a reachable SpdyFrameCodec pipeline.
PoC
[poc.zip](https://github.com/user-attachments/files/28445780/poc.zip)
run with:
bash ./poc/run.sh
expected output:
NETTY_SPDY_ZLIB_DECODED_AFTER_LIMIT_TRIGGERED compressed_bytes=12253 declared_name_length=12582912 max_header_size=16 truncated=true invalid=false
The fingerprint means the compressed input was fully consumed while the raw header parser ended with truncated=true and invalid=false after processing the oversized decoded name. That specific state distinguishes this bug from a generic setup failure: the maxHeaderSize guard fired, but the zlib/raw decode path still inflated and skipped the full 12 MiB declared name.
Impact
A remote unauthenticated peer that can speak SPDY to a Netty pipeline containing SpdyFrameCodec can send a small compressed HEADERS block that expands into much larger raw header data after the configured maxHeaderSize limit has already been exceeded. The attack requires a reachable SPDY codec, ordinary transport setup such as TCP and optional TLS, and no independent compressed-frame-size or connection-rate limit ahead of SpdyFrameCodec. The satisfied protocol guards are straightforward: the HEADERS frame uses a nonzero stream id and length >= 4, the decoder factory selects the zlib decoder, the payload uses the SPDY dictionary, and the raw block appends a zero-length value so the already-truncated frame reaches END_HEADER_BLOCK. The user-visible effect is denial of service through compression-amplified CPU and allocation churn.
Details
- Affected product:
- Apache CXF , Apache Hadoop , Apache Kafka , Apache Log4j , Apache Maven , Apache Solr , Apache Spark , Eclipse Jetty , Elasticsearch , Netty , Spring , Wildfly , alluxio , amazon-kinesis-client , amqp-10-jms-spring-boot , artemis , async-http-client , avro , aws-sdk-java , aws-sdk-java-v2 , azure-sdk-for-java , azure-search-documents , bolt-connection-java , bookkeeper , bookkeeper-common-allocator , camel , cassandra-java-driver , corda , couchbase-jvm-clients , couchbase-jvm-clients-core-io , couchbase-jvm-clients-java-client , curator , cypher-dsl , distributedlog , docker-java , etcd4j , flink , flink-shaded , flume , googleapis , grpc-java , hbase , hbase-thirdparty , infinispan , jaeger-analytics-java , java-datastore , java-driver , jersey , lettuce , logging-flume , metrics , micrometer , micronaut-core , neo4j-java-driver , neo4j-ogm , olingo-odata4 , pinecone-java-client , pulsar , qpid-jms , rabbitmq-java-client , rabbitmq-stream-java-client , redisson , ribbon , rsocket-java , rxnetty , sdk-platform-java , testcontainers-java , tika , vert.x , zendesk-java-client , zookeeper
- Affected packages:
- Spring Integration @ 5.5.19 (+14087 more)