PT-2026-81028 · Netty · Netty
CVE-2026-76816
·
Published
2026-08-24
·
Updated
2026-08-25
CVSS v3.1
3.5
Low
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Netty versions prior to 4.1.137.Final
Netty versions prior to 4.2.17.Final
Description
Netty is an asynchronous, event-driven network application framework. The
MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding. This allows prohibited null bytes in MQTT UTF-8 string fields, which can lead to routing, access-control, or identity mismatches in downstream brokers. The issue occurs when an application uses the MQTT encoder to construct messages from user-controlled input.Recommendations
Update to version 4.1.137.Final.
Update to version 4.2.17.Final.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netty