Junglewise Threat Intelligence

CVE-2026-93575: Netty MqttDecoder MQTT packet validation bypass

CVE-2026-93575 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: Netty. Vendors: Netty.

Executive brief

Netty is a widely-used Java networking library that handles MQTT protocol communication for IoT and messaging applications. An attacker can send a malformed MQTT packet to crash services using Netty's MQTT decoder, causing denial of service through excessive memory and CPU consumption that exhausts available system resources.

Technical details

The MqttDecoder in Netty fails to properly validate the relationship between the 'Properties Length' and 'Remaining Length' fields in MQTT CONNECT packets, allowing an unauthenticated remote attacker to bypass decoder size limits. This vulnerability enables an attacker to trigger OutOfMemoryError conditions via specially crafted MQTT packets, resulting in denial of service. The flaw requires no authentication and can be exploited over the network.

Affected products

  • Netty Netty <UNKNOWN>

Timeline

  • 2026-09-18: disclosed

References

Related threats