Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
See https://github.com/netty/netty/security/advisories/GHSA-jqf3-r9ww-c5x8 for fixed versions and remediation guidance.
Sat, 19 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `Remaining Length` exceeds `maxBytesInMessage`, but fails to validate the `Properties Length` against the `Remaining Length`. An attacker can bypass the size limit by sending a small `Remaining Length` but an enormous `Properties Length`. This forces Netty to buffer and parse millions of properties, allowing an unauthenticated remote attacker to trigger excessive memory and CPU consumption, leading to OutOfMemoryError. ### Details In `io.netty.handler.codec.mqtt.MqttDecoder`, the `decodeProperties()` helper method reads `totalPropertiesLength` and attempts to parse that many bytes. If the buffer lacks the full length, a `Signal` is thrown. The `catch` block inside `decode()` only enforces `maxBytesInMessage` against `bytesRemainingBeforeVariableHeader` (the packet's `Remaining Length`). By sending a `CONNECT` packet with a small `Remaining Length` but a huge `Properties Length`, the size check passes. `ReplayingDecoder` then buffers data from the network until the huge `Properties Length` is reached, parsing millions of `UserProperty` objects and exhausting CPU and memory. # | A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Length', allowing an attacker to bypass size limits. This leads to excessive memory and CPU consumption, resulting in a denial of service (DoS) due to an OutOfMemoryError. |
Fri, 18 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Netty: netty-codec-mqtt: io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder | Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder |
Fri, 18 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 18 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `Remaining Length` exceeds `maxBytesInMessage`, but fails to validate the `Properties Length` against the `Remaining Length`. An attacker can bypass the size limit by sending a small `Remaining Length` but an enormous `Properties Length`. This forces Netty to buffer and parse millions of properties, allowing an unauthenticated remote attacker to trigger excessive memory and CPU consumption, leading to OutOfMemoryError. ### Details In `io.netty.handler.codec.mqtt.MqttDecoder`, the `decodeProperties()` helper method reads `totalPropertiesLength` and attempts to parse that many bytes. If the buffer lacks the full length, a `Signal` is thrown. The `catch` block inside `decode()` only enforces `maxBytesInMessage` against `bytesRemainingBeforeVariableHeader` (the packet's `Remaining Length`). By sending a `CONNECT` packet with a small `Remaining Length` but a huge `Properties Length`, the size check passes. `ReplayingDecoder` then buffers data from the network until the huge `Properties Length` is reached, parsing millions of `UserProperty` objects and exhausting CPU and memory. # | |
| Title | Netty: netty-codec-mqtt: io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder | |
| First Time appeared |
Redhat
Redhat amq Broker Redhat camel Spring Boot Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-1035 | |
| CPEs | cpe:/a:redhat:amq_broker:7 cpe:/a:redhat:camel_spring_boot:4 cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat amq Broker Redhat camel Spring Boot Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat red Hat Single Sign On |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-18T20:12:15.535Z
Reserved: 2026-09-18T10:32:41.197Z
Link: CVE-2026-93575
No data.
Status : Awaiting Analysis
Published: 2026-09-18T11:17:22.033
Modified: 2026-09-18T21:18:48.427
Link: CVE-2026-93575
OpenCVE Enrichment
Updated: 2026-09-19T01:00:09Z