CVE-2026-76816 - Netty: MQTT Topic Name and Client ID Validation Bypass
Brief
CVE ID : CVE-2026-76816
Published : Aug. 24, 2026, 8:17 p. m.
- 54 minutes ago
Description : Netty is an asynchronous, event-driven network application framework. Prior to versions 4.
- 137. Final and 4.
- 17. Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohibited null bytes in MQTT UTF-8 string fields and potentially causing routing, access-control, or identity mismatches in downstream brokers.
The vulnerability is exploitable when an application uses Netty's MQTT encoder to construct messages from user-controlled input. This issue is fixed in versions 4.
- 137. Final and 4.
- 17. Final.
Severity: 3.5
- LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
