CVE-2026-93488: Red Hat Amq Broker 7
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY connection and send a large number of SYN_STREAM frames with FLAG_FIN=0, causing unbounded heap and direct memory allocation that can lead to JVM OutOfMemoryError and a denial of service.
Affected products
- Red Hat Red Hat Amq Broker 7
- Red Hat Red Hat Amq Clients
- Red Hat Red Hat Build Of Apache Camel 3.33.3.sp2: before 4.1.138.Final-redhat-00001 (fixed in 4.1.138.Final-redhat-00001)
- Red Hat Red Hat Build Of Apache Camel 4 For Quarkus 3
- Red Hat Red Hat Build Of Apache Camel For Spring Boot 4
- Red Hat Red Hat Build Of Apicurio Registry 3
- Red Hat Red Hat Build Of Debezium 3
- Red Hat Red Hat Build Of Keycloak
- Red Hat Red Hat Build Of Quarkus 3.27.5.sp2
- Red Hat Red Hat Build Of Quarkus 3.33.3.sp2
- Red Hat Red Hat Data Grid 8
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat Single Sign-On 7
Published 2026-09-18. Last modified 2026-10-10.