CVE-2026-44890 PUBLISHED

Netty has Unbounded Direct Memory Consumption in its RedisDecoder

Assigner: GitHub_M
Reserved: 07.05.2026 Published: 11.06.2026 Updated: 12.06.2026

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without \r\n. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor netty
Product netty
Versions
  • Version >= 4.2.0.Final, < 4.2.15.Final is affected
  • Version < 4.1.135.Final is affected

References

Problem Types

  • CWE-400: Uncontrolled Resource Consumption CWE