Red HatCVE-2026-93575
Red Hat Netty: resource exhaustion
High7.5CVE-2026-93575 · Published Sep 18, 2026 · updated Sep 25, 2026
A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Length', allowing an attacker to bypass size limits. This leads to excessive memory and CPU consumption, resulting in a denial of service (DoS) due to an OutOfMemoryError.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat AMQ Broker 7 Product | all versions | No fix yet |
| Red Hat Fuse 7 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform 7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Apache Camel for Spring Boot 4 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-1035
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 18 | Red Hat OpenShift Container Platform 4: server-side request forgery | Critical9.3 | No fix yet |
| Sep 18 | Red Hat Netty: request smuggling | Medium6.5 | No fix yet |
| Sep 18 | Red Hat Netty: request smuggling | Medium6.5 | No fix yet |
| Sep 18 | A flaw was found in cockpit-files | Medium6.1 | No fix yet |
| Sep 18 | Red Hat cockpit-files. This vulnerability: race condition | Medium6.0 | No fix yet |
| Sep 18 | Red Hat cockpit-files: race condition | Medium6.0 | No fix yet |