{ "schema_version": "1.4.0", "id": "GHSA-v74w-7mr3-4qg3", "modified": "2026-08-13T14:25:43Z", "published": "2026-07-24T16:53:04Z", "aliases": [ "CVE-2026-73507" ], "summary": "Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion", "details": "### Summary\nAn attacker can cause Denial of Service by sending a specially crafted malicious XML payload (e.g., repeated ``.\nBecause the parser state is not saved between `decode()` invocations, an attacker can trickle-feed a payload of `