CVE-2026-93560: Red Hat Build Of Apache Camel For Spring Boot 4

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite decode loop, causing a Denial of Service (DoS) by exhausting memory and CPU resources.

Affected products

  • Red Hat Red Hat Build Of Apache Camel For Spring Boot 4
  • Red Hat Red Hat Fuse 7
  • Red Hat Red Hat JBoss Enterprise Application Platform 7
  • Red Hat Red Hat Single Sign-On 7

Published 2026-09-18. Last modified 2026-09-22.