Description
A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Length', allowing an attacker to bypass size limits. This leads to excessive memory and CPU consumption, resulting in a denial of service (DoS) due to an OutOfMemoryError.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service through resource exhaustion
Action: Patch Update
AI Analysis

Impact

Netty’s MqttDecoder does not validate the Properties Length field against the Remaining Length when parsing an MQTT CONNECT packet. An unauthenticated remote attacker can send a specially crafted CONNECT request that causes the decoder to allocate excessive memory and consume CPU, eventually triggering an OutOfMemoryError and bringing the application or service to a halt. This weakness corresponds to CWE‑1035, a resource exhaustion flaw caused by improper bounds checking.

Affected Systems

The flaw affects Red Hat AMQ Broker 7, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign‑On 7, and the Red Hat build of Apache Camel for Spring Boot 4. Any deployment using the vulnerable Netty library version is at risk, regardless of the host operating system or underlying infrastructure.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability rates as high to critical in terms of impact. The EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog, yet it can be exploited remotely over the MQTT protocol without authentication. An attacker only needs network access to the MQTT port to trigger the denial of service, making the risk significant for exposed or poorly segmented workloads.

Generated by OpenCVE AI on September 19, 2026 at 16:27 UTC.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-jqf3-r9ww-c5x8 for fixed versions and remediation guidance.


OpenCVE Recommended Actions

  • Upgrade Netty to a version that includes the MQTT decoder fix as recommended in the vendor advisory
  • Follow the GitHub advisory’s guidance to apply the documented workaround, such as enforcing strict Properties Length limits or disabling MQTT support when not required
  • Block or rate-limit incoming MQTT CONNECT traffic at the network perimeter to reduce exposure until a patch is deployed

Generated by OpenCVE AI on September 19, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat fuse 7
Redhat single Sign-on
Vendors & Products Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat fuse 7
Redhat single Sign-on

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description ### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `Remaining Length` exceeds `maxBytesInMessage`, but fails to validate the `Properties Length` against the `Remaining Length`. An attacker can bypass the size limit by sending a small `Remaining Length` but an enormous `Properties Length`. This forces Netty to buffer and parse millions of properties, allowing an unauthenticated remote attacker to trigger excessive memory and CPU consumption, leading to OutOfMemoryError. ### Details In `io.netty.handler.codec.mqtt.MqttDecoder`, the `decodeProperties()` helper method reads `totalPropertiesLength` and attempts to parse that many bytes. If the buffer lacks the full length, a `Signal` is thrown. The `catch` block inside `decode()` only enforces `maxBytesInMessage` against `bytesRemainingBeforeVariableHeader` (the packet's `Remaining Length`). By sending a `CONNECT` packet with a small `Remaining Length` but a huge `Properties Length`, the size check passes. `ReplayingDecoder` then buffers data from the network until the huge `Properties Length` is reached, parsing millions of `UserProperty` objects and exhausting CPU and memory. # A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Length', allowing an attacker to bypass size limits. This leads to excessive memory and CPU consumption, resulting in a denial of service (DoS) due to an OutOfMemoryError.

Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Netty: netty-codec-mqtt: io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Fri, 18 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description ### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `Remaining Length` exceeds `maxBytesInMessage`, but fails to validate the `Properties Length` against the `Remaining Length`. An attacker can bypass the size limit by sending a small `Remaining Length` but an enormous `Properties Length`. This forces Netty to buffer and parse millions of properties, allowing an unauthenticated remote attacker to trigger excessive memory and CPU consumption, leading to OutOfMemoryError. ### Details In `io.netty.handler.codec.mqtt.MqttDecoder`, the `decodeProperties()` helper method reads `totalPropertiesLength` and attempts to parse that many bytes. If the buffer lacks the full length, a `Signal` is thrown. The `catch` block inside `decode()` only enforces `maxBytesInMessage` against `bytesRemainingBeforeVariableHeader` (the packet's `Remaining Length`). By sending a `CONNECT` packet with a small `Remaining Length` but a huge `Properties Length`, the size check passes. `ReplayingDecoder` then buffers data from the network until the huge `Properties Length` is reached, parsing millions of `UserProperty` objects and exhausting CPU and memory. #
Title Netty: netty-codec-mqtt: io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder
First Time appeared Redhat
Redhat amq Broker
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
Weaknesses CWE-1035
CPEs cpe:/a:redhat:amq_broker:7
cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat amq Broker
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
References

Subscriptions

Io.netty Netty-codec-http
Redhat Amq Broker Build Of Apache Camel For Spring Boot Camel Spring Boot Fuse 7 Jboss Enterprise Application Platform Jboss Fuse Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T08:29:03.072Z

Reserved: 2026-09-18T10:32:41.197Z

Link: CVE-2026-93575

cve-icon Vulnrichment

Updated: 2026-09-22T14:18:52.829Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T11:17:22.033

Modified: 2026-09-25T09:17:07.647

Link: CVE-2026-93575

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:53:24Z

Links: CVE-2026-93575 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:53Z

Weaknesses