Impact
The vulnerability is an unbounded per‑connection queue growth in the WebSocketServerExtensionHandler component of Netty. When a WebSocket client sends messages, the handler may enqueue them without a cap, allowing an attacker to exhaust available memory or system resources. The result is a denial of service that can affect the affected application or the container hosting it. Failure to control queue size leads to resource depletion, and the weakness is classified under CWE‑1035.
Affected Systems
Affected vendors include Red Hat products that incorporate the Netty library, such as Red Hat AMQ Broker 7, Red Hat AMQ Clients, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, and Red Hat build of Quarkus 3. The version range is unspecified in the entry, so systems should check whether they include the Netty component vulnerable to this class of queue‑growth issues. Red Hat identifies the impacted product families but does not list specific sub‑versions, so any installation that includes the current Netty 4.x or 5.x packages is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.5 denotes a moderately high severity impact, and the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalogue, suggesting no widespread or documented live exploitation. Based on the description, the likely attack vector is via a malicious WebSocket connection that repeatedly sends data, causing the unbounded queue to grow until the service becomes unresponsive. The exploit requires network access to the target endpoint that accepts WebSocket upgrades. An attacker could trigger multiple concurrent WebSocket sessions to amplify resource exhaustion. The vulnerability has no broader privilege escalation or data breach implications, but it can effectively deny service to legitimate users.
OpenCVE Enrichment