Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c39-fwgj-4vq7

Опубликовано: 01 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and CoordinatorServer by sending specially crafted frame headers, resulting in denial of service.

This issue affects Apache Fluss (incubating): 0.8.0 and 0.9.0.

Users are recommended to upgrade to version 0.9.1, which fixes the issue.

Пакеты

Наименование

org.apache.fluss:fluss-common

maven
Затронутые версииВерсия исправления

>= 0.8.0-incubating-rc1, < 0.9.1-incubating

0.9.1-incubating

EPSS

Процентиль: 45%
0.00581
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and CoordinatorServer by sending specially crafted frame headers, resulting in denial of service. This issue affects Apache Fluss (incubating): 0.8.0 and 0.9.0. Users are recommended to upgrade to version 0.9.1, which fixes the issue.

EPSS

Процентиль: 45%
0.00581
Низкий

7.5 High

CVSS3

Дефекты

CWE-400