CVE-2026-44250
🟡 Monitoruj
Atak DoS w netty-codec-redis umożliwia wyczerpanie pamięci przez złośliwe dane.
CVSS
7.5
EPSS
0.5%
Exploit
none
Vendor
netty
Opis źródłowy (NVD)
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2026-06-11 22:16:56 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-18 13:18:24 UTC |
Referencje
- https://github.com/netty/netty/releases/tag/netty-4.1.135.Final ([email protected]) [Release Notes]
- https://github.com/netty/netty/releases/tag/netty-4.2.15.Final ([email protected]) [Release Notes]
- https://github.com/netty/netty/security/advisories/GHSA-3244-j874-rhc2 ([email protected]) [Vendor Advisory]
- https://access.redhat.com/errata/RHSA-2026:37390 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:41951 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:50085 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:53644 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:53645 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:53646 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/security/cve/CVE-2026-44250 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://bugzilla.redhat.com/show_bug.cgi?id=2488062 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44250.json (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)