PT-2026-81028 · Netty · Netty

CVE-2026-76816

·

Published

2026-08-24

·

Updated

2026-08-25

CVSS v3.1

3.5

Low

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.137.Final Netty versions prior to 4.2.17.Final
Description Netty is an asynchronous, event-driven network application framework. The MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding. This allows prohibited null bytes in MQTT UTF-8 string fields, which can lead to routing, access-control, or identity mismatches in downstream brokers. The issue occurs when an application uses the MQTT encoder to construct messages from user-controlled input.
Recommendations Update to version 4.1.137.Final. Update to version 4.2.17.Final.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76816
GHSA-43FM-7CXG-HF3J

Affected Products

Netty