Aias00 opened a new issue, #6639:
URL: https://github.com/apache/shenyu/issues/6639

   - severity: High
   - files: 
`shenyu-protocol/shenyu-protocol-mqtt/src/main/java/org/apache/shenyu/protocol/mqtt/MqttTransportHandler.java:32-39`;
 `Publish.java:46-57,115-126`
   - description: `MqttTransportHandler extends ChannelInboundHandlerAdapter` 
(not `SimpleChannelInboundHandler`), so inbound messages are not auto-released, 
and the handler never calls `ReferenceCountUtil.release(msg)`. The 
`MqttPublishMessage` payload ByteBuf is leaked on every PUBLISH. Additionally 
`CompletableFuture.runAsync(() -> send(topic, payload, packetId))` hands the 
same payload ByteBuf to `Unpooled.wrappedBuffer(payload)` for every subscriber 
channel in parallel with no per-write retain.
   - impact: Native/pooled buffer leak per PUBLISH; potential 
`IllegalReferenceCountException` or buffer corruption under multi-subscriber 
fan-out.
   - suggested_fix: Release inbound message in `channelRead` (or extend 
`SimpleChannelInboundHandler`); `payload.retainedDuplicate()` per subscriber 
write.
   - confidence: High
   - related_existing: none
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to