Impact
The vulnerability is a reference-count leak in Netty's HAProxy PROXY‑v2 codec: a nested TLV grandchild ByteBuf is not released. An attacker can send specially crafted PROXY‑v2 headers to a vulnerable application, causing incremental memory inflation that eventually exhausts heap space and results in a service failure. The flaw allows remote, unauthenticated traffic to trigger the leak, leading to denial of service for the affected system.
Affected Systems
The affected systems include multiple Red Hat products that embed Netty, such as Red Hat AMQ Broker 7, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign‑On 7, the Red Hat build of Keycloak, the Red Hat build of Apache Camel for Quarkus 3, the Red Hat build of Apache Camel for Spring Boot 4, the Red Hat build of Apicurio Registry 3, the Red Hat build of Debezium 3, and the Red Hat build of Quarkus. No specific version range is listed; any product that includes the vulnerable Netty codec may be impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate‑to‑high severity, and the EPSS score of less than 1% shows a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to send traffic that uses the HAProxy PROXY‑v2 protocol to the vulnerable application; a crafted message could trigger the leak, gradually depleting memory and eventually causing a service disruption.
OpenCVE Enrichment