CVE-2026-42586Disclosure(netty / netty)

LOWCVSS 7.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch netty netty systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netty

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
netty

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-13: 3Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-13: 205-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets5 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42586 Netty is an asynchronous, event-driven network application framework. Prior to http://4.2.13.Final and http://4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes use… https://www.cve.org/CVERecord?id=CVE-2026-42586 ----- Traducció… http://infoflow.cloud`

    Post summary

    This tweet announces CVE‑2026‑42586 for Netty, notes affected pre‑release versions, and links to the CVE record, indicating the vulnerability has been disclosed and is addressed in newer releases.

    0000031
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42586 Netty is an asynchronous, event-driven network application framework. Prior to http://4.2.13.Final and http://4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes use… https://www.cve.org/CVERecord?id=CVE-2026-42586

    Post summary

    The text identifies CVE‑2026‑42586 as a vulnerability in Netty’s Redis codec encoder in versions prior to 4.2.13.Final and 4.1.133.Final, referencing the CVE record but providing no further technical detail, proof‑of‑concept, or mitigation information.

    00000242
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42586 Command Injection in Netty Redis Codec Encoder Prior to http://4.2.13.Final and http://4.1.133.Final https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42586

    Post summary

    The entry identifies a command injection flaw in Netty Redis Codec Encoder, affecting versions prior to 4.2.13.Final and 4.1.133.Final, with no indication of PoC, exploit code, or active exploitation.

    0000051
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnettynetty---

Explore more