PT-2026-99328 · Unknown · Netty Stomp Codec

·

CVE-2026-100657

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netty STOMP codec versions prior to 4.1.138.Final Netty STOMP codec versions 4.2.0.Final through 4.2.17.Final
Description A ByteBuf leak exists in the StompSubframeDecoder function. When a frame's declared content-length is fully read, the decoder allocates a chunk buffer and waits for the terminating NUL byte. If this byte is not received, the buffer is not released because the signal thrown by skipNullCharacter() extends Error instead of Exception, bypassing the release path. Additionally, the decoder does not override handlerRemoved0 or channelInactive, allowing the buffer to persist after channel teardown. A remote peer can trigger this leak by sending a well-formed frame body without the terminating NUL byte, potentially leading to memory exhaustion as the pooled allocator does not reclaim the memory.
Recommendations Update to version 4.1.138.Final or later. Update to version 4.2.18.Final or later.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100657
GHSA-GHG5-C4JG-8Q5J

Affected Products

Netty Stomp Codec