Menu

#215 Yajsw Netty Upgrade to Address CVE-2026-44891

All
open-accepted
nobody
None
5
2026-08-14
2026-08-12
REVATHI V
No

CVE ID: CVE-2026-44891

Affected Yajsw Version: 13.18, 14.00

Vulnerable Dependency: Netty v4.2.6.Final

Impact:

Netty versions prior to 4.2.16.Final are vulnerable to a denial-of-service issue in io.netty.handler.codec.stomp.StompSubframeDecoder. An attacker can send a STOMP frame containing a large number of short headers, causing excessive memory consumption and potentially resulting in an OutOfMemoryError, leading to denial of service for servers exposing a STOMP endpoint. The vulnerability has a CVSS score of 7.5 (High).

Solution:

Upgrade the Yajsw Netty dependency from v4.2.x.Final to v4.2.16.Final.

Recommended Fix Version: Netty v4.2.16.Final

Reference:

https://nvd.nist.gov/vuln/detail/CVE-2026-44891

Discussion

  • rzo

    rzo - 2026-08-14
    • status: open --> open-accepted
     
  • rzo

    rzo - 2026-08-14

    thanks for reporting.

     

Log in to post a comment.