Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-93494

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.

Отчет

This is an Important flaw in Netty's STOMP codec that allows a remote, unauthenticated attacker to cause a permanent memory leak. By sending an incomplete STOMP frame, an attacker can consume allocator memory that is never reclaimed, leading to a denial of service over time. This issue is particularly impactful as the memory leak persists even after the connection is closed, making it difficult to detect and prevent with standard connection-based rate limiting.

Меры по смягчению последствий

See https://github.com/netty/netty/security/advisories/GHSA-ghg5-c4jg-8q5j for fixed versions and remediation guidance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4netty-codec-stompAffected
Red Hat Fuse 7netty-codec-stompAffected
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk11-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk17-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk8-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7netty-codec-stompWill not fix
Red Hat Single Sign-On 7netty-codec-stompAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1035
https://bugzilla.redhat.com/show_bug.cgi?id=2536898io.netty/netty-codec-stomp: Netty: ByteBuf Leak in StompSubframeDecoder When a Frame Body Is Never Terminated

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
3 дня назад

A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.

CVSS3: 7.5
debian
3 дня назад

A flaw was found in Netty's StompSubframeDecoder component. A remote a ...

CVSS3: 7.5
github
3 дня назад

A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.

7.5 High

CVSS3