CVE-2026-42586
גבוהה 7.1
תיאור (מקור, אנגלית)
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
מדדים
- CVSS 3.1
-
7.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-4/8/2026
- CWE
- CWE-93
מוצרים מושפעים
netty: netty
קישורים
- https://github.com/netty/netty/security/advisories/GHSA-rgrr-p7gp-5xj7 ExploitMitigationVendor Advisory
- https://github.com/netty/netty/security/advisories/GHSA-rgrr-p7gp-5xj7 ExploitMitigationVendor Advisory