oss-sec mailing list archives

CVE-2026-49361: Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability


From: Jark Wu <jark () apache org>
Date: Sat, 30 May 2026 15:19:31 +0000

Severity: important 

Affected versions:

- Apache Fluss (incubating) 0.8.0
- Apache Fluss (incubating) 0.9.0

Description:

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the 
maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and 
CoordinatorServer by sending specially crafted frame headers, resulting in denial of service.

This issue affects Apache Fluss (incubating): 0.8.0 and 0.9.0.

Users are recommended to upgrade to version 0.9.1, which fixes the issue.

Credit:

Andrea Cosentino (reporter)

References:

https://fluss.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-49361


Current thread: