Количество 7
Количество 7
GHSA-5w86-c3rq-vjj7
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
CVE-2026-50011
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CVE-2026-50011
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CVE-2026-50011
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CVE-2026-50011
Netty is a network application framework for development of protocol s ...
BDU:2026-08453
Уязвимость компонента RedisArrayAggregator фреймворка для разработки сетевых приложений, серверов и клиентов протоколов Netty, позволяющая нарушителю оказать воздействие на доступность защищаемой информации
SUSE-SU-2026:2802-1
Security update for netty, netty-tcnative
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-5w86-c3rq-vjj7 Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50011 Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50011 Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50011 Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-50011 Netty is a network application framework for development of protocol s ... | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
BDU:2026-08453 Уязвимость компонента RedisArrayAggregator фреймворка для разработки сетевых приложений, серверов и клиентов протоколов Netty, позволяющая нарушителю оказать воздействие на доступность защищаемой информации | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
SUSE-SU-2026:2802-1 Security update for netty, netty-tcnative | 28 дней назад |
Уязвимостей на страницу