CVE-2026-44891
גבוהה 7.5
תיאור (מקור, אנגלית)
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-3/8/2026
- CWE
- CWE-400, CWE-770
מוצרים מושפעים
netty: netty
קישורים
- https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp ExploitVendor Advisory
- https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp ExploitVendor Advisory
- https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b Patch
- https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 Patch
- https://github.com/netty/netty/pull/17063 Issue TrackingPatch
- https://github.com/netty/netty/pull/17065 Issue TrackingPatch
- https://github.com/netty/netty/releases/tag/netty-4.1.136.Final Release Notes
- https://github.com/netty/netty/releases/tag/netty-4.2.16.Final Release Notes