Impact
The vulnerability resides in Netty’s HttpServerCodec component. By sending a series of pipelined HTTP/1.1 requests on a single connection and intentionally postponing read operations, an unauthenticated remote attacker can cause the internal methodOverflowQueue to grow without bounds. This leads to uncontrolled heap memory consumption, ultimately exhausting system memory and resulting in a denial of service. The weakness is classified as a resource exploitation flaw (CWE‑770). The attack does not provide code execution or privilege escalation; it merely disrupts availability.
Affected Systems
The flaw affects several Red Hat products that incorporate Netty 4.x, including Red Hat AMQ Broker 7, AMQ Clients, the build of Keycloak, Data Grid 8, Fuse 7, JBoss Enterprise Application Platform 7 and 8, JBoss Single Sign‑On 7, the build of Apache Camel 4 for Quarkus 3, the build of Apache Camel for Spring Boot 4, the build of Apicurio Registry 3, the build of Debezium 3, and the build of Quarkus 3. No specific version ranges are listed, so all releases using the vulnerable Netty code are potentially affected.
Risk and Exploitability
The CVSS score of 7.5 marks this as high severity, and the exploit does not require authentication, making it widely accessible to any remote actor who can reach the affected HTTP service. The EPSS score is under 1 %, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the lack of an available workaround means that exposed services face a significant risk of resource exhaustion. Monitoring for unusual memory usage and limiting inbound traffic still provide the best chance of preventing a successful denial‑of‑service attack.
OpenCVE Enrichment