Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42586

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

A flaw was found in Netty, an asynchronous, event-driven network application framework. The Netty Redis codec encoder (RedisEncoder) does not properly validate or sanitize user-controlled string content for CRLF (Carriage Return Line Feed) characters. A remote attacker, by controlling the content of a Redis message, can inject arbitrary Redis commands or forge fake responses. This can lead to a high impact on data integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7netty-codec-redisOut of support scope
Red Hat JBoss Enterprise Application Platform 7netty-codec-redisNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packnetty-codec-redisNot affected
Red Hat Process Automation 7netty-codec-redisWill not fix
Red Hat Single Sign-On 7netty-codec-redisWill not fix
Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16netty-codec-redisFixedRHSA-2026:3739009.07.2026
Red Hat Data Grid 8.6.2netty-codec-redisFixedRHSA-2026:4195120.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-93
https://bugzilla.redhat.com/show_bug.cgi?id=2477213netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder

EPSS

Процентиль: 10%
0.00198
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 6.8
nvd
3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 6.8
debian
3 месяца назад

Netty is an asynchronous, event-driven network application framework. ...

CVSS3: 6.8
github
3 месяца назад

Netty Redis Codec Encoder has a CRLF Injection Issue

CVSS3: 8.1
fstec
3 месяца назад

Уязвимость компонента io.netty.handler.codec.redis.RedisEncoder фреймворка для разработки сетевых приложений, серверов и клиентов протоколов Netty, позволяющая нарушителю внедрить произвольные команды

EPSS

Процентиль: 10%
0.00198
Низкий

6.8 Medium

CVSS3