CVE-2026-93494
Netty: netty-codec-stomp: io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.
| CWE | CWE-1035 |
| Vendor | red hat |
| Product | red hat build of apache camel for spring boot 4 |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for red hat red hat build of apache camel for spring boot 4
Be the first to know when new unknown vulnerabilities affecting red hat red hat build of apache camel for spring boot 4 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Red Hat / Red Hat build of Apache Camel for Spring Boot 4
All versions affected Red Hat / Red Hat Fuse 7
All versions affected Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected Red Hat / Red Hat JBoss Enterprise Application Platform 7
All versions affected Red Hat / Red Hat Single Sign-On 7
All versions affected