Impact
A flaw in Netty’s StompSubframeDecoder allows a remote actor to send a STOMP frame body that lacks the required terminating null byte. The decoder keeps a ByteBuf buffer that is never released, creating a permanent memory leak. Over time, the uncontrolled growth of allocated memory can bring the application into a state where it cannot allocate resources, ultimately causing a denial of service. The weakness is a classic resource‑management bug, classified as CWE‑1035.
Affected Systems
Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign‑On 7, and the Red Hat build of Apache Camel for Spring Boot 4 are affected. Versions of these products that incorporate the Netty‑codec‑stomp component prior to the fixed release are vulnerable. Precise version ranges are not listed in the advisory, so any deployment of the affected products that has not been updated remains at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity impact, but the EPSS score of below 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers must be able to send forged STOMP frames to the application; thus, the attack vector is remote, network‑based. If exploited, the memory leak will persist until the application is restarted or a patch is applied, providing conditions for a DoS attack.
OpenCVE Enrichment