cve-2026-73507

HIGH CVSS 7.5 csaf_redhat
Description

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

Timeline
Published
2026-08-13 14:25 UTC
Last Modified
2026-08-26
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73507.json"
      }
    ],
    "title": "io.netty/netty-codec-xml: Netty: Denial of Service via CPU Exhaustion in XmlFrameDecoder",
    "tracking": {
      "current_release_date": "2026-08-26T21:58:23+00:00",
      "generator": {
        "date": "2026-08-26T21:58:23+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.16"
        }
      },
      "id": "CVE-2026-73507",
      "initial_release_date": "2026-08-13T14:25:34.073000+00:00",
      "revision_history": [
        {
          "date": "2026-08-13T14:25:34.073000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-26T21:50:32+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-26T21:58:23+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat build of Apache Camel for Spring Boot 4",
                "product": {
                  "name": "Red Hat build of Apache Camel for Spring Boot 4",
                  "product_id": "red_hat_build_of_apache_camel_for_spring_boot_4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:camel_spring_boot:4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat build of Apache Camel for Spring Boot 4"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 7",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 7",
                  "product_id": "red_hat_jboss_enterprise_application_platform_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Single Sign-On 7",
                "product": {
                  "name": "Red Hat Single Sign-On 7",
                  "product_id": "red_hat_single_sign-on_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Single Sign-On 7"
          },
          {
            "category": "product_version",
            "name": "netty-codec-xml",
            "product": {
              "name": "netty-codec-xml",
              "product_id": "netty-codec-xml",
              "product_identification_helper": {
                "purl": "pkg:maven/io.netty/netty-codec-xml@4.1.136.Final-redhat-00001"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jboss-eap-7/eap74-els-openjdk11-openshift-rhel8",
            "product": {
              "name": "jboss-eap-7/eap74-els-openjdk11-openshift-rhel8",
              "product_id": "jboss-eap-7/eap74-els-openjdk11-openshift-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/eap74-els-openjdk11-openshift-rhel8?repository_url=registry.redhat.io/jboss-eap-7/eap74-els-openjdk11-openshift-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jboss-eap-7/eap74-els-openjdk17-openshift-rhel8",
            "product": {
              "name": "jboss-eap-7/eap74-els-openjdk17-openshift-rhel8",
              "product_id": "jboss-eap-7/eap74-els-openjdk17-openshift-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/eap74-els-openjdk17-openshift-rhel8?repository_url=registry.redhat.io/jboss-eap-7/eap74-els-openjdk17-openshift-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jboss-eap-7/eap74-els-openjdk8-openshift-rhel8",
            "product": {
              "name": "jboss-eap-7/eap74-els-openjdk8-openshift-rhel8",
              "product_id": "jboss-eap-7/eap74-els-openjdk8-openshift-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/eap74-els-openjdk8-openshift-rhel8?repository_url=registry.redhat.io/jboss-eap-7/eap74-els-openjdk8-openshift-rhel8"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "netty-codec-xml as a component of Red Hat build of Apache Camel for Spring Boot 4",
          "product_id": "red_hat_build_of_apache_camel_for_spring_boot_4:netty-codec-xml"
        },
        "product_reference": "netty-codec-xml",
        "relates_to_product_reference": "red_hat_build_of_apache_camel_for_spring_boot_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7",
          "product_id": "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk11-openshift-rhel8"
        },
        "product_reference": "jboss-eap-7/eap74-els-openjdk11-openshift-rhel8",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7",
          "product_id": "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk17-openshift-rhel8"
        },
        "product_reference": "jboss-eap-7/eap74-els-openjdk17-openshift-rhel8",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7",
          "product_id": "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk8-openshift-rhel8"
        },
        "product_reference": "jboss-eap-7/eap74-els-openjdk8-openshift-rhel8",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "netty-codec-xml as a component of Red Hat JBoss Enterprise Application Platform 7",
          "product_id": "red_hat_jboss_enterprise_application_platform_7:netty-codec-xml"
        },
        "product_reference": "netty-codec-xml",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "netty-codec-xml as a component of Red Hat Single Sign-On 7",
          "product_id": "red_hat_single_sign-on_7:netty-codec-xml"
        },
        "product_reference": "netty-codec-xml",
        "relates_to_product_reference": "red_hat_single_sign-on_7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73507",
      "cwe": {
        "id": "CWE-835",
        "name": "Loop with Unreachable Exit Condition ('Infinite Loop')"
      },
      "discovery_date": "2026-08-13T15:11:27.106908+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk11-openshift-rhel8",
            "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk17-openshift-rhel8",
            "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk8-openshift-rhel8",
            "red_hat_jboss_enterprise_application_platform_7:netty-codec-xml"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2515374"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Netty's XmlFrameDecoder component. An unauthenticated remote attacker could send specially crafted XML closing-tag sequences. This could cause the system to repeatedly rescan accumulated data, leading to high CPU utilization and a denial of service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "io.netty/netty-codec-xml: Netty: Denial of Service via CPU Exhaustion in XmlFrameDecoder",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "A flaw was found in Netty's XmlFrameDecoder component within the netty-codec-xml library. Red Hat products including JBoss EAP 7, Red Hat Fuse 7, Red Hat Single Sign-On 7, and Red Hat Integration Camel Spring Boot ship the netty-codec-xml library. However, these products do not utilize the XmlFrameDecoder class for XML processing. The vulnerable code path, which handles reassembly of fragmented XML messages across network frames, is not instantiated or exercised in Red Hat product deployments. This vulnerability only affects custom applications that explicitly use XmlFrameDecoder to parse untrusted XML input from network streams.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_build_of_apache_camel_for_spring_boot_4:netty-codec-xml",
          "red_hat_single_sign-on_7:netty-codec-xml"
        ],
        "known_not_affected": [
          "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk11-openshift-rhel8",
          "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk17-openshift-rhel8",
          "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk8-openshift-rhel8",
          "red_hat_jboss_enterprise_application_platform_7:netty-codec-xml"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-73507"
        },
        {
          "category": "external",
          "summary": "RHBZ#2515374",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2515374"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-73507",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-73507"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-73507",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73507"
        },
        {
          "category": "external",
          "summary": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"
        },
        {
          "category": "external",
          "summary": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"
        },
        {
          "category": "external",
          "summary": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"
        },
        {
          "category": "external",
          "summary": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"
        },
        {
          "category": "external",
          "summary": "https://github.com/netty/netty/security/advisories/GHSA-v74w-7mr3-4qg3",
          "url": "https://github.com/netty/netty/security/advisories/GHSA-v74w-7mr3-4qg3"
        }
      ],
      "release_date": "2026-08-13T14:25:34.073000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "Red Hat products do not use the vulnerable XmlFrameDecoder component. No mitigation is required for standard product deployments. Custom applications built on Red Hat middleware that explicitly instantiate XmlFrameDecoder should avoid processing untrusted XML input or upgrade to netty-codec-xml 4.1.136.Final or later.",
          "product_ids": [
            "red_hat_build_of_apache_camel_for_spring_boot_4:netty-codec-xml",
            "red_hat_single_sign-on_7:netty-codec-xml"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_build_of_apache_camel_for_spring_boot_4:netty-codec-xml",
            "red_hat_single_sign-on_7:netty-codec-xml"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_build_of_apache_camel_for_spring_boot_4:netty-codec-xml",
            "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk11-openshift-rhel8",
            "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk17-openshift-rhel8",
            "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk8-openshift-rhel8",
            "red_hat_jboss_enterprise_application_platform_7:netty-codec-xml",
            "red_hat_single_sign-on_7:netty-codec-xml"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_build_of_apache_camel_for_spring_boot_4:netty-codec-xml",
            "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk11-openshift-rhel8",
            "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk17-openshift-rhel8",
            "red_hat_jboss_enterprise_application_platform_7:jboss-eap-7/eap74-els-openjdk8-openshift-rhel8",
            "red_hat_jboss_enterprise_application_platform_7:netty-codec-xml",
            "red_hat_single_sign-on_7:netty-codec-xml"
          ]
        }
      ],
      "title": "io.netty/netty-codec-xml: Netty: Denial of Service via CPU Exhaustion in XmlFrameDecoder"
    }
  ]
}
Enrichment data
View JSON API Download JSON