CVE-2026-44250High· 7.5▾ TwilightNetty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nes…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
0.4% → 0.5%
Last analysed / modified upstream
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
netty < 4.1.135netty >= 4.2.0, < 4.2.15Upgrade past the affected range:
netty 4.2.15Affected packages:
io.netty:netty-codec-redis >= 4.2.0.Final, <= 4.2.14.Finalio.netty:netty-codec-redis <= 4.1.134.FinalPatched in:
io.netty:netty-codec-redis 4.2.15.Finalio.netty:netty-codec-redis 4.1.135.FinalSource: https://github.com/advisories/GHSA-3244-j874-rhc2
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44890High· 7.5Netty is a network application framework for development of protocol servers and clients
CVE-2026-50011High· 7.5Netty is a network application framework for development of protocol servers and clients
CVE-2026-42587High· 7.5Netty is an asynchronous, event-driven network application framework
CVE-2026-46340High· 7.5Netty is a network application framework for development of protocol servers and clients
CVE-2026-48043Medium· 5.3Netty is a network application framework for development of protocol servers and clients
CVE-2026-44248Medium· 5.3Netty is an asynchronous, event-driven network application framework