← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 20:17via CVEFeed

CVE-2026-76816 - Netty: MQTT Topic Name and Client ID Validation Bypass

Brief

CVE ID : CVE-2026-76816

Published : Aug. 24, 2026, 8:17 p. m.

  • 54 minutes ago

Description : Netty is an asynchronous, event-driven network application framework. Prior to versions 4.

  • 137. Final and 4.
  • 17. Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohibited null bytes in MQTT UTF-8 string fields and potentially causing routing, access-control, or identity mismatches in downstream brokers.

The vulnerability is exploitable when an application uses Netty's MQTT encoder to construct messages from user-controlled input. This issue is fixed in versions 4.

  • 137. Final and 4.
  • 17. Final.

Severity: 3.5

  • LOW

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed