Improper Handling of Highly Compressed Data (Data Amplification) Affecting candlepin-selinux package, versions *


Severity

Recommended
0.0
high
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.42% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL7-CANDLEPINSELINUX-18367617
  • published28 Jul 2026
  • disclosed20 Jul 2026

Introduced: 20 Jul 2026

NewCVE-2026-55833  (opens in a new tab)
CWE-409  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:7 candlepin-selinux.

NVD Description

Note: Versions mentioned in the description apply only to the upstream candlepin-selinux package and not the candlepin-selinux package as distributed by RHEL. See How to fix? for RHEL:7 relevant fixed versions and status.

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded maxHeaderSize and marked the frame truncated in SpdyFrameCodec, allowing a remote peer to send a small compressed HEADERS block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS Base Scores

version 3.1