CVE-2026-44248
netty netty, netty-codec-mqtt, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 취약점
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, N...
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.49% 백분위 39.4% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.05.14