PT-2026-47602 · Netty · Netty
Published
2026-06-08
·
Updated
2026-06-08
·
CVE-2026-44890
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Netty (affected versions not specified)
Description
A Denial of Service (DoS) issue exists where an attacker can exhaust the server's direct memory pool, leading to an
OutOfDirectMemoryError and preventing legitimate connections. This occurs because the decodeLength function in io.netty.handler.codec.redis.RedisDecoder reads bytes from the network until a character is encountered but does not enforce a maximum length check while buffering. An attacker can exploit this by opening multiple concurrent connections and sending a continuous stream of digits without the required r termination specified in the RESP protocol, causing the system to buffer data indefinitely.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty