CVE-2026-76816CWE-20CWE-626

CVE-2026-76816

Low · published August 25, 2026

CVSS v3.1
3.5
EPSS
0%
Percentile
7.0
In the wild
Unconfirmed
What it is

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohibited null bytes in MQTT UTF-8 string fields and potentially causing routing, access-control, or identity mismatches in downstream brokers. The vulnerability is exploitable when an application uses Netty's MQTT encoder to construct messages from user-controlled input. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.

The record
Technical detail
CVSS v3.1
3.5 · LOW
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00174 · 7.0th percentile
Weaknesses
CWE-20 · Improper Input Validation; CWE-626 · Null Byte Interaction Error (Poison Null Byte)
Published
2026-08-25T00:17Z
References (3)
EPSS history
Timeline
  • 26 AUG 08:27Z
    EPSS moved — → 0%
    epss
  • 24 AUG 19:53Z
    Netty: MQTT Topic Name and Client ID Validation Bypass
    cvelistv5