GHSA-jfg9-48mv-9qgx
Netty MQTT: Resource exhaustion in MqttDecoder
Quick fix
GHSA-jfg9-48mv-9qgx — io.netty:netty-codec-mqtt: upgrade to the fixed version with the command below.
# pom.xml: bump <version>4.2.13.Final</version> for io.netty:netty-codec-mqttDetails
### Impact The MQTT 5 header Properties section is parsed and buffered _before_ any message size limit is applied.
Specifically, in `MqttDecoder`, the `decodeVariableHeader()` method is called before the `bytesRemainingBeforeVariableHeader > maxBytesInMessage` check. The `decodeVariableHeader()` can call other methods which will call `decodeProperties()`. Effectively, Netty does not apply any limits to the size of the properties being decoded.
Additionally, because `MqttDecoder` extends `ReplayingDecoder`, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion.
This can cause high resource usage in both CPU and memory.
### Resources `ANT-2026-09608` https://docs.oasis-open.org/mqtt/mqtt/v5.0/os/mqtt-v5.0-os.html#_Toc3901027
Are you affected?
Enter the version of the package you're using.
Affected packages
4.2.0.Alpha1Fixed in: 4.2.13.Final# pom.xml: bump <version>4.2.13.Final</version> for io.netty:netty-codec-mqtt0Fixed in: 4.1.133.Final# pom.xml: bump <version>4.1.133.Final</version> for io.netty:netty-codec-mqtt