Skip to main content
Loading…
    CVE-2026-49361 — Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap — CVE Database · The Intelligence Room