CVE-2026-93494: Netty: netty-codec-stomp: io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated

Published Sep 18, 2026
·
Updated

A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.

Affected Software

1 affected component
maven/io.netty/netty-codec-stomp

Event History

Sep 18, 2026
CVE Published
via MITRE·07:39 AM
Data Sourced
via MITRE·07:39 AM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments should be prioritized for triage?

Applications that use the Maven dependency io.netty:netty-codec-stomp and process STOMP frames from remote clients should be prioritized, because the affected decoder is StompSubframeDecoder.

2

Is a fixed version or temporary workaround identified?

The provided information does not identify a fixed version or a workaround. It only identifies the affected Maven component as io.netty:netty-codec-stomp.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203