A vulnerability identified as problematic has been detected in netty netty-codec-http3 up to 3.QpackD/4.2.13.Final. This affects the function in.readableBytes. The manipulation leads to allocation of resources.

This vulnerability is documented as CVE-2026-42582. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.