Status: UPDATED
| Advisory ID: CVE-2026-93575
Key Details
| CVE | CVE-2026-93575 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-25 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | Red Hat Red Hat JBoss Enterprise Application Platform 7, Red Hat Red Hat Single Sign-On 7, Red Hat Red Hat build of Apache Camel for Spring Boot 4, and Red Hat Red Hat AMQ Broker 7 |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Length', allowing an attacker to bypass size limits. This leads to excessive memory and CPU consumption, resulting in a denial of service (DoS) due to an OutOfMemoryError. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References