Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
See https://github.com/netty/netty/security/advisories/GHSA-wxrh-4rgq-pjcg for fixed versions and remediation guidance.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Io.netty
Io.netty netty-codec-http Redhat build Of Apache Camel For Spring Boot Redhat quay 3 Redhat rsingle Sign-on |
|
| Vendors & Products |
Io.netty
Io.netty netty-codec-http Redhat build Of Apache Camel For Spring Boot Redhat quay 3 Redhat rsingle Sign-on |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can lead to frame desynchronization and response smuggling, where one client's data may be inadvertently exposed to another client's response stream in proxy or cache environments. |
| Metrics |
ssvc
|
Fri, 18 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Netty: netty-codec-memcache: io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling | Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling |
Fri, 18 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 18 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 18 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling | |
| Title | Netty: netty-codec-memcache: io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling | |
| First Time appeared |
Redhat
Redhat camel Spring Boot Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-1035 | |
| CPEs | cpe:/a:redhat:camel_spring_boot:4 cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat camel Spring Boot Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat red Hat Single Sign On |
|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-18T20:18:54.565Z
Reserved: 2026-09-18T09:47:37.249Z
Link: CVE-2026-93561
Updated: 2026-09-18T14:54:26.760Z
Status : Awaiting Analysis
Published: 2026-09-18T11:17:21.650
Modified: 2026-09-18T21:18:46.847
Link: CVE-2026-93561
OpenCVE Enrichment
Updated: 2026-09-21T19:25:56Z