Resource Exhaustion Affecting trino-plugin-exchange-filesystem package, versions <482-r0


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.42% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-TRINOPLUGINEXCHANGEFILESYSTEM-17986930
  • published16 Jul 2026
  • disclosed17 Jul 2026

Introduced: 16 Jul 2026

NewCVE-2026-44891  (opens in a new tab)
CWE-400  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade Minimos:latest trino-plugin-exchange-filesystem to version 482-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream trino-plugin-exchange-filesystem package and not the trino-plugin-exchange-filesystem package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS Base Scores

version 3.1