Description
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory leak
Action: Apply Patch
AI Analysis

Impact

A flaw in Netty’s StompSubframeDecoder allows a remote actor to send a STOMP frame body that lacks the required terminating null byte. The decoder keeps a ByteBuf buffer that is never released, creating a permanent memory leak. Over time, the uncontrolled growth of allocated memory can bring the application into a state where it cannot allocate resources, ultimately causing a denial of service. The weakness is a classic resource‑management bug, classified as CWE‑1035.

Affected Systems

Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign‑On 7, and the Red Hat build of Apache Camel for Spring Boot 4 are affected. Versions of these products that incorporate the Netty‑codec‑stomp component prior to the fixed release are vulnerable. Precise version ranges are not listed in the advisory, so any deployment of the affected products that has not been updated remains at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity impact, but the EPSS score of below 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers must be able to send forged STOMP frames to the application; thus, the attack vector is remote, network‑based. If exploited, the memory leak will persist until the application is restarted or a patch is applied, providing conditions for a DoS attack.

Generated by OpenCVE AI on September 19, 2026 at 20:54 UTC.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-ghg5-c4jg-8q5j for fixed versions and remediation guidance.


OpenCVE Recommended Actions

  • Upgrade Netty to the fixed release or apply the vendor‑issued security patch for Red Hat Fuse 7, JBoss EAP 7, Single Sign‑On 7, or Apache Camel for Spring Boot 4, following the guidance in Red Hat’s advisory.
  • If an immediate update is unavailable, isolate the affected service by restricting incoming STOMP traffic to trusted networks or by blocking the STOMP protocol at the perimeter firewall.
  • Apply any temporary code–level workaround described in the Netty GitHub advisory (GHSA‑ghg5‑c4jg‑8q5j) while awaiting the official patch.

Generated by OpenCVE AI on September 19, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3
Redhat single Sign-on
Vendors & Products Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3
Redhat single Sign-on

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Netty: netty-codec-stomp: io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated

Fri, 18 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.
Title Netty: netty-codec-stomp: io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated
First Time appeared Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
Weaknesses CWE-1035
CPEs cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
References

Subscriptions

Io.netty Netty-codec-http
Redhat Build Of Apache Camel For Spring Boot Camel Spring Boot Jboss Enterprise Application Platform Jboss Fuse Quay 3 Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T08:02:02.576Z

Reserved: 2026-09-18T07:19:20.917Z

Link: CVE-2026-93494

cve-icon Vulnrichment

Updated: 2026-09-18T19:36:17.485Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T08:17:02.647

Modified: 2026-09-25T09:17:07.150

Link: CVE-2026-93494

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:42:12Z

Links: CVE-2026-93494 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:57Z

Weaknesses