CVE-2026-49361

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
01/06/2026
Last modified:
01/06/2026

Description

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and CoordinatorServer by sending specially crafted frame headers, resulting in denial of service.<br /> <br /> This issue affects Apache Fluss (incubating): 0.8.0 and 0.9.0.<br /> <br /> Users are recommended to upgrade to version 0.9.1, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:fluss:*:*:*:*:*:*:*:* 0.8.0 (including) 0.9.1 (excluding)