High severity7.5NVD Advisory· Published Jun 1, 2026· Updated Jul 22, 2026
CVE-2026-49361
CVE-2026-49361
Description
Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and CoordinatorServer by sending specially crafted frame headers, resulting in denial of service.
This issue affects Apache Fluss (incubating): 0.8.0 and 0.9.0.
Users are recommended to upgrade to version 0.9.1, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.fluss:fluss-commonMaven | >= 0.8.0-incubating-rc1, < 0.9.1-incubating | 0.9.1-incubating |
Affected products
2Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2026/05/30/5nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-4c39-fwgj-4vq7ghsaADVISORY
- lists.apache.org/thread/dccw6tj0njwtmvbftq13mw7fdhsok373nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-49361ghsaADVISORY
- github.com/apache/fluss/releases/tag/v0.9.1-incubatingghsaWEB
News mentions
0No linked articles in our index yet.