PT-2026-45385 · Apache · Apache Fluss

·

CVE-2026-49361

·

Published

2026-06-01

·

Updated

2026-06-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Fluss versions prior to 0.9.1
Description The Netty LengthFieldBasedFrameDecoder is configured with Integer.MAX VALUE as the maximum frame length. This allows unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and CoordinatorServer by sending specially crafted frame headers, leading to a denial of service.
Recommendations Upgrade to version 0.9.1.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49361
GHSA-4C39-FWGJ-4VQ7

Affected Products

Apache Fluss