Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4882 articles · 221206 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-93558PATCHED
red hat · red hat amq broker

Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service

Description

A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consuming excessive memory. Eventually, this can cause the Java Virtual Machine (JVM) to exhaust its heap, resulting in a Denial of Service (DoS) for the affected server.

Affected Products

VendorProductVersions
red hatred hat amq broker—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcenettycert_advisory90%

References

  • https://access.redhat.com/errata/RHSA-2026:69440(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:69470(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:70257(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-93558(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2536932(issue-tracking, x_refsource_REDHAT)

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [hoch] Netty: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-93558 | Red Hat AMQ Broker WebSocketServerExtensionHandler denial of service
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://access.redhat.com/errata/RHSA-2026:69470
CWECWE-1035
PublishedSep 18, 2026
Last enriched4d ago
Trending Score41
Source articles2
Independent2
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-94184EXP
Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)
Trending: 59
NONECVE-2026-87766EXP
Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup
Trending: 55
NONECVE-2026-93676EXP
Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks
Trending: 49
NONECVE-2026-93562
Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling
Trending: 41
NONECVE-2026-95511
Cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial backend (cups2root)
Trending: 41

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Sep 18, 2026
Discovered by ZDM
Sep 18, 2026
Patch Available
Sep 22, 2026