VDB
Sign up
MEDIUM5.3

GHSA-jfg9-48mv-9qgx

Netty MQTT: Resource exhaustion in MqttDecoder

Quick fix

GHSA-jfg9-48mv-9qgx — io.netty:netty-codec-mqtt: upgrade to the fixed version with the command below.

# pom.xml: bump <version>4.2.13.Final</version> for io.netty:netty-codec-mqtt

Details

### Impact The MQTT 5 header Properties section is parsed and buffered _before_ any message size limit is applied.

Specifically, in `MqttDecoder`, the `decodeVariableHeader()` method is called before the `bytesRemainingBeforeVariableHeader > maxBytesInMessage` check. The `decodeVariableHeader()` can call other methods which will call `decodeProperties()`. Effectively, Netty does not apply any limits to the size of the properties being decoded.

Additionally, because `MqttDecoder` extends `ReplayingDecoder`, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion.

This can cause high resource usage in both CPU and memory.

### Resources `ANT-2026-09608` https://docs.oasis-open.org/mqtt/mqtt/v5.0/os/mqtt-v5.0-os.html#_Toc3901027

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.netty:netty-codec-mqtt
Introduced in: 4.2.0.Alpha1Fixed in: 4.2.13.Final
Fix# pom.xml: bump <version>4.2.13.Final</version> for io.netty:netty-codec-mqtt
Maven/io.netty:netty-codec-mqtt
Introduced in: 0Fixed in: 4.1.133.Final
Fix# pom.xml: bump <version>4.1.133.Final</version> for io.netty:netty-codec-mqtt

References