Impact
Netty’s MqttDecoder does not validate the Properties Length field against the Remaining Length when parsing an MQTT CONNECT packet. An unauthenticated remote attacker can send a specially crafted CONNECT request that causes the decoder to allocate excessive memory and consume CPU, eventually triggering an OutOfMemoryError and bringing the application or service to a halt. This weakness corresponds to CWE‑1035, a resource exhaustion flaw caused by improper bounds checking.
Affected Systems
The flaw affects Red Hat AMQ Broker 7, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign‑On 7, and the Red Hat build of Apache Camel for Spring Boot 4. Any deployment using the vulnerable Netty library version is at risk, regardless of the host operating system or underlying infrastructure.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability rates as high to critical in terms of impact. The EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog, yet it can be exploited remotely over the MQTT protocol without authentication. An attacker only needs network access to the MQTT port to trigger the denial of service, making the risk significant for exposed or poorly segmented workloads.
OpenCVE Enrichment