Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-42586

Опубликовано: 13 мая 2026
Источник: nvd
CVSS3: 6.8
CVSS3: 7.1
EPSS Низкий

Описание

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
Версия до 4.1.133 (исключая)
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 4.2.13 (исключая)

EPSS

Процентиль: 10%
0.00198
Низкий

6.8 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 6.8
ubuntu
3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 6.8
redhat
3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 6.8
debian
3 месяца назад

Netty is an asynchronous, event-driven network application framework. ...

CVSS3: 6.8
github
3 месяца назад

Netty Redis Codec Encoder has a CRLF Injection Issue

CVSS3: 8.1
fstec
3 месяца назад

Уязвимость компонента io.netty.handler.codec.redis.RedisEncoder фреймворка для разработки сетевых приложений, серверов и клиентов протоколов Netty, позволяющая нарушителю внедрить произвольные команды

EPSS

Процентиль: 10%
0.00198
Низкий

6.8 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-93