CVE-2026-93560
- EPSS 0.41%
- Veröffentlicht 18.09.2026 13:44:20
- Zuletzt bearbeitet 22.09.2026 15:17:23
A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite decode loop, cau...
CVE-2026-93563
- EPSS 0.33%
- Veröffentlicht 18.09.2026 10:58:35
- Zuletzt bearbeitet 25.09.2026 09:17:07
A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without a terminator....
CVE-2026-93572
- EPSS 0.34%
- Veröffentlicht 18.09.2026 10:53:54
- Zuletzt bearbeitet 25.09.2026 09:17:07
A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly preallocate a large am...
CVE-2026-93575
- EPSS 0.39%
- Veröffentlicht 18.09.2026 10:53:48
- Zuletzt bearbeitet 25.09.2026 09:17:07
A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Lengt...
CVE-2026-93561
- EPSS 0.18%
- Veröffentlicht 18.09.2026 10:02:36
- Zuletzt bearbeitet 25.09.2026 09:17:07
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit thi...
CVE-2026-93494
- EPSS 0.41%
- Veröffentlicht 18.09.2026 07:39:17
- Zuletzt bearbeitet 25.09.2026 09:17:07
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer fo...
CVE-2026-84218
- EPSS 0.88%
- Veröffentlicht 01.09.2026 13:20:27
- Zuletzt bearbeitet 02.09.2026 09:16:39
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolok...
CVE-2026-81624
- EPSS 0.33%
- Veröffentlicht 31.08.2026 08:47:51
- Zuletzt bearbeitet 10.09.2026 08:16:59
Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted a...
CVE-2026-5680
- EPSS 0.4%
- Veröffentlicht 27.08.2026 16:25:29
- Zuletzt bearbeitet 22.09.2026 16:17:49
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction....
CVE-2026-14180
- EPSS 0.41%
- Veröffentlicht 11.08.2026 15:32:00
- Zuletzt bearbeitet 22.09.2026 16:17:37
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chu...