VYPR
High severity7.5NVD Advisory· Published Jun 11, 2026· Updated Jun 15, 2026

CVE-2026-44890

CVE-2026-44890

Description

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without \r\n. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.netty:netty-codec-redisMaven
>= 4.2.0.Final, < 4.2.15.Final4.2.15.Final
io.netty:netty-codec-redisMaven
< 4.1.135.Final4.1.135.Final

Affected products

38

Patches

Vulnerability mechanics

References

5

News mentions

3