Unknown · Netty Stomp Codec · CVE-2026-100657
**Name of the Vulnerable Software and Affected Versions**
Netty STOMP codec versions prior to 4.1.138.Final
Netty STOMP codec versions 4.2.0.Final through 4.2.17.Final
**Description**
A ByteBuf leak exists in the `StompSubframeDecoder` function. When a frame's declared content-length is fully read, the decoder allocates a chunk buffer and waits for the terminating NUL byte. If this byte is not received, the buffer is not released because the signal thrown by `skipNullCharacter()` extends Error instead of Exception, bypassing the release path. Additionally, the decoder does not override `handlerRemoved0` or `channelInactive`, allowing the buffer to persist after channel teardown. A remote peer can trigger this leak by sending a well-formed frame body without the terminating NUL byte, potentially leading to memory exhaustion as the pooled allocator does not reclaim the memory.
**Recommendations**
Update to version 4.1.138.Final or later.
Update to version 4.2.18.Final or later.