CVE-2026-93558: CWE-1035 in Red Hat Red Hat AMQ Broker 7
A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consuming excessive memory. Eventually, this can cause the Java Virtual Machine (JVM) to exhaust its heap, resulting in a Denial of Service (DoS) for the affected server.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-93558 affects Red Hat AMQ Broker 7. It is caused by unbounded growth of per-connection queues within the WebSocketServerExtensionHandler, which can be exploited to cause a denial of service by resource exhaustion. The CVSS 3.1 base score is 7.5, reflecting a network attack vector with no privileges or user interaction required, and impacts availability only. No vendor advisory details on patch availability or affected versions are provided beyond the advisory URL.
Potential Impact
Successful exploitation results in denial of service due to resource exhaustion from unbounded queue growth. There is no impact on confidentiality or integrity. The service may become unavailable or unresponsive, affecting availability to legitimate users.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-93558 for current remediation guidance. Until a fix is applied, consider limiting WebSocket connection rates or applying resource usage controls if possible.
CVE-2026-93558: CWE-1035 in Red Hat Red Hat AMQ Broker 7
Description
A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consuming excessive memory. Eventually, this can cause the Java Virtual Machine (JVM) to exhaust its heap, resulting in a Denial of Service (DoS) for the affected server.
CVSS v3.1
Score 7.5high
Affected software
Red Hat
Red Hat AMQ Broker 7
Red Hat
Red Hat AMQ Clients
Red Hat
Red Hat build of Apache Camel 4 for Quarkus 3
Red Hat
Red Hat build of Apache Camel for Spring Boot 4
Red Hat
Red Hat build of Apicurio Registry 3
Red Hat
Red Hat build of Debezium 3
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat build of Quarkus
Red Hat
Red Hat Data Grid 8
Red Hat
Red Hat Fuse 7
Red Hat
Red Hat JBoss Enterprise Application Platform 7
Red Hat
Red Hat JBoss Enterprise Application Platform 8
Red Hat
Red Hat Single Sign-On 7
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-93558 affects Red Hat AMQ Broker 7. It is caused by unbounded growth of per-connection queues within the WebSocketServerExtensionHandler, which can be exploited to cause a denial of service by resource exhaustion. The CVSS 3.1 base score is 7.5, reflecting a network attack vector with no privileges or user interaction required, and impacts availability only. No vendor advisory details on patch availability or affected versions are provided beyond the advisory URL.
Potential Impact
Successful exploitation results in denial of service due to resource exhaustion from unbounded queue growth. There is no impact on confidentiality or integrity. The service may become unavailable or unresponsive, affecting availability to legitimate users.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-93558 for current remediation guidance. Until a fix is applied, consider limiting WebSocket connection rates or applying resource usage controls if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-18T09:41:56.676Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-93558","vendor":"Red Hat"}]
Threat ID: 6aad4b7355bf5e2cf51f5ecf
Added to database: 09/18/2026, 14:32:19 UTC
Last enriched: 09/18/2026, 14:46:49 UTC
Last updated: 09/18/2026, 23:17:27 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.