Missing Release of Resource after Effective Lifetime in Netty - #VU148881
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of a resource after its effective lifetime in StompSubframeDecoder when processing a STOMP frame body without its terminating NUL byte. A remote attacker can send a complete STOMP frame body while omitting its terminating byte to cause a denial of service.