Improper Check or Handling of Exceptional Conditions Affecting io.netty:netty-codec-redis package, versions [,4.1.136.Final)[4.2.0-Final,4.2.16.Final)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.46% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Check or Handling of Exceptional Conditions vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-IONETTY-18592369
  • published8 Aug 2026
  • disclosed7 Aug 2026
  • creditUnknown

Introduced: 7 Aug 2026

NewCVE-2026-56818  (opens in a new tab)
CWE-401  (opens in a new tab)
CWE-703  (opens in a new tab)

How to fix?

Upgrade io.netty:netty-codec-redis to version 4.1.136.Final, 4.2.16.Final or higher.

Overview

Affected versions of this package are vulnerable to Improper Check or Handling of Exceptional Conditions in the RedisArrayAggregator process. An attacker can cause retained partial aggregate state to persist by sending a RESP array with a bulk-string child followed by a nested array header that exceeds the configured maxElements limit, resulting in a decoder exception without proper cleanup. This allows attacker-controlled aggregate state to remain alive across a security-limit exception, potentially pinning retained pooled buffers until the channel is closed or the handler is removed.

CVSS Base Scores

version 4.0
version 3.1