CVE-2026-49361

CVE-2026-49361: Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability

Vendor Apache Software Foundation
Product Apache Fluss (incubating)
Weakness CWE-770 · Uncontrolled resource consumption
Published June 1, 2026
Last update June 1, 2026

CVSS base score

What the vulnerability does

Description

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and CoordinatorServer by sending specially crafted frame headers, resulting in denial of service. This issue affects Apache Fluss (incubating): 0.8.0 and 0.9.0. Users are recommended to upgrade to version 0.9.1, which fixes the issue.

Key dates

Disclosure timeline

June 1, 2026 CVE published
June 1, 2026 Record updated