High severity7.5NVD Advisory· Published Jun 12, 2026· Updated Jun 15, 2026
CVE-2026-50011
CVE-2026-50011
Description
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.netty:netty-codec-redisMaven | >= 4.2.0.Final, < 4.2.15.Final | 4.2.15.Final |
io.netty:netty-codec-redisMaven | < 4.1.135.Final | 4.1.135.Final |
Affected products
10- osv-coords8 versionspkg:apk/chainguard/celeborn-0.6pkg:apk/chainguard/management-api-for-apache-cassandra-5.0pkg:apk/chainguard/pinot-fipspkg:apk/chainguard/thingsboard-tb-nodepkg:apk/wolfi/celeborn-0.6pkg:apk/wolfi/management-api-for-apache-cassandra-5.0pkg:apk/wolfi/thingsboard-tb-nodepkg:rpm/opensuse/netty&distro=openSUSE%20Tumbleweed
< 0.6.3-r8+ 7 more
- (no CPE)range: < 0.6.3-r8
- (no CPE)range: < 0.1.120-r0
- (no CPE)range: < 1.5.0-r11
- (no CPE)range: < 4.3.1.2-r13
- (no CPE)range: < 0.6.3-r8
- (no CPE)range: < 0.1.120-r0
- (no CPE)range: < 4.3.1.2-r13
- (no CPE)range: < 4.1.135-1.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-5w86-c3rq-vjj7ghsaADVISORY
- github.com/netty/netty/security/advisories/GHSA-5w86-c3rq-vjj7nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-50011ghsaADVISORY
- github.com/netty/netty/releases/tag/netty-4.1.135.FinalnvdRelease NotesWEB
- github.com/netty/netty/releases/tag/netty-4.2.15.FinalnvdRelease NotesWEB
News mentions
0No linked articles in our index yet.