A vulnerability marked as critical has been reported in Netty up to 4.1.135/4.2.15. This affects an unknown function of the component STOMP Encoder. The manipulation leads to injection.

This vulnerability is uniquely identified as CVE-2026-59920. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.