netty-codec-stomp vulnerabilities
CVEs whose affected-version data names the netty-codec-stomp package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-93560High· 7.5A flaw was found in the Netty STOMP codec
A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite dec…
▾ TwilightRed Hat · netty-codec-stompEPSS 0.41%via NVD
CVE-2026-93494High· 7.5A flaw was found in Netty's StompSubframeDecoder component
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf…
▾ TwilightRed Hat · netty-codec-stompEPSS 0.41%via NVD