{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-93565/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93494"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Netty","Netty (\u003c 4.2.13.Final)"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","vulnerability","netty","cve-2026-93565","rtsp","input-validation"],"_cs_type":"advisory","_cs_vendors":["Netty"],"content_html":"\u003cp\u003eA memory leak vulnerability (CVE-2026-93494) exists within the StompSubframeDecoder component of the Netty framework. The flaw is triggered when an attacker sends a STOMP frame body that lacks the expected terminating null byte. Upon receiving such a frame, the decoder performs a ByteBuf allocation that is never subsequently released by the application logic. Because the allocation persists in memory, repeated submission of these crafted frames leads to cumulative, uncontrolled memory consumption. This resource exhaustion eventually causes the host application to crash or become unresponsive, effectively resulting in a Denial of Service (DoS) for any services utilizing the affected STOMP codec. Defenders should prioritize identifying applications leveraging Netty for STOMP protocol handling to evaluate exposure and schedule patches.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a Denial of Service for applications relying on the Netty StompSubframeDecoder. Persistent memory exhaustion can impact availability for any service exposed to untrusted STOMP traffic, potentially forcing service restarts or leading to total system instability if the memory limit is reached.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all internal and customer-facing applications that utilize the Netty framework, specifically those incorporating the StompSubframeDecoder component.\u003c/li\u003e\n\u003cli\u003eReview vendor release notes and security advisories for the Netty project to identify the specific patched version containing the fix for CVE-2026-93494.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided patch to all vulnerable Netty implementations.\u003c/li\u003e\n\u003cli\u003eMonitor memory utilization metrics for services handling STOMP traffic to detect potential exploitation attempts causing memory pressure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T16:08:18Z","date_published":"2026-09-18T12:05:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netty-stomp-dos/","summary":"A memory leak vulnerability in the Netty StompSubframeDecoder component (CVE-2026-93494) allows remote attackers to cause a Denial of Service by sending malformed STOMP frames.","title":"Denial of Service Vulnerability in Netty StompSubframeDecoder","url":"https://feed.craftedsignal.io/briefs/2026-09-netty-stomp-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-93565","version":"https://jsonfeed.org/version/1.1"}