Junglewise Threat Intelligence

CVE-2026-93494: Netty memory leak in StompSubframeDecoder

CVE-2026-93494 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: Netty Project Netty. Vendors: Netty Project.

Executive brief

Netty is a popular Java networking library used to build high-performance network applications and messaging systems. A flaw in its STOMP (Streaming Text Oriented Messaging Protocol) decoder allows a remote attacker to trigger a memory leak by sending malformed protocol frames, eventually exhausting available memory and causing the application to become unresponsive or crash.

Technical details

The StompSubframeDecoder in Netty fails to release a ByteBuf when processing a STOMP frame body that is missing its terminating null byte, causing an unreleased buffer object and permanent memory leak. An attacker with network access can send specially crafted STOMP frames to trigger repeated buffer allocation without cleanup, leading to Denial of Service through memory exhaustion. A fix is implied to exist as this is a reported vulnerability with a CVE identifier.

Affected products

  • Netty Project Netty

Timeline

  • 2026-09-18: disclosed

References

Related threats