CWE-1035

CWE-1035 · 3 records · 0 with a public proof-of-concept

Records the NVD classes under CWE-1035, highest CVSS first.

  1. HIGH 7.5CVE-2026-93575

    A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Length', allowi…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-93563

    A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without a terminator. This vuln…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.5CVE-2026-93561

    A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mis…

    AI risk analysis on Exploit-DB.ai →