CVE-2026-93491: Allocation of Resources Without Limits or Throttling in Red Hat Red Hat AMQ Broker 7
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.
AI Analysis
Technical Summary
This vulnerability arises from an unbounded queue in Netty's HttpServerCodec that tracks pipelined HTTP/1.1 requests. A remote attacker can exploit this by sending multiple pipelined requests without reading responses, causing the methodOverflowQueue to grow without limit. This results in unbounded heap memory consumption and denial of service due to memory exhaustion in applications using affected Netty versions, including Red Hat AMQ Broker 7. Red Hat has published an advisory confirming the issue but currently does not offer a mitigation or fix that meets their standards for ease of use, applicability, or stability.
Potential Impact
The vulnerability allows a remote, unauthenticated attacker to cause denial of service by exhausting heap memory through unbounded resource allocation. This leads to potential service unavailability in affected applications. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
Red Hat currently states that no mitigation is available or that existing options do not meet their criteria for deployment and stability. Users should monitor Red Hat advisories for updates. Applying a fix is not currently possible; consider contacting Red Hat Technical Account Managers if applicable. Avoid exposure of vulnerable services to untrusted networks where possible.
CVE-2026-93491: Allocation of Resources Without Limits or Throttling in Red Hat Red Hat AMQ Broker 7
Description
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.
CVSS v3.1
Score 7.5high
Affected software
Red Hat
Red Hat AMQ Broker 7
Red Hat
Red Hat AMQ Clients
Red Hat
Red Hat build of Apache Camel 4 for Quarkus 3
Red Hat
Red Hat build of Apache Camel for Spring Boot 4
Red Hat
Red Hat build of Apicurio Registry 3
Red Hat
Red Hat build of Debezium 3
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat build of Quarkus
Red Hat
Red Hat Data Grid 8
Red Hat
Red Hat Fuse 7
Red Hat
Red Hat JBoss Enterprise Application Platform 7
Red Hat
Red Hat JBoss Enterprise Application Platform 8
Red Hat
Red Hat Single Sign-On 7
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from an unbounded queue in Netty's HttpServerCodec that tracks pipelined HTTP/1.1 requests. A remote attacker can exploit this by sending multiple pipelined requests without reading responses, causing the methodOverflowQueue to grow without limit. This results in unbounded heap memory consumption and denial of service due to memory exhaustion in applications using affected Netty versions, including Red Hat AMQ Broker 7. Red Hat has published an advisory confirming the issue but currently does not offer a mitigation or fix that meets their standards for ease of use, applicability, or stability.
Potential Impact
The vulnerability allows a remote, unauthenticated attacker to cause denial of service by exhausting heap memory through unbounded resource allocation. This leads to potential service unavailability in affected applications. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
Red Hat currently states that no mitigation is available or that existing options do not meet their criteria for deployment and stability. Users should monitor Red Hat advisories for updates. Applying a fix is not currently possible; consider contacting Red Hat Technical Account Managers if applicable. Avoid exposure of vulnerable services to untrusted networks where possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-18T07:14:15.353Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-93491","vendor":"Red Hat"}]
Threat ID: 6aad365d55bf5e2cf507faef
Added to database: 09/18/2026, 13:02:21 UTC
Last enriched: 09/18/2026, 13:16:36 UTC
Last updated: 09/19/2026, 02:07:13 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.