VDB
CVE-2026-50011
CVE-2026-50011
PUBLISHED
CVSS 7.5 HIGH
Reported by GitHub_M · Published June 12, 2026
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| netty | netty | >= 4.2.0.Final, < 4.2.15.Final, < 4.1.135.Final |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | 0:2.18.8-1.redhat_00003.1.el7eap, 0:2.18.8-1.redhat_00003.1.el7eap |
| wolfi | thingsboard | 0, 0, 0 |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | 0:4.1.135-1.Final_redhat_00001.1.el7eap, 0:4.1.135-1.Final_redhat_00001.1.el7eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | 0:2.18.8-1.redhat_00003.1.el7eap, 0:2.18.8-1.redhat_00003.1.el7eap |
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | |
| Red Hat | Red Hat Fuse 7 | |
| chainguard | thingsboard | 0, 0, 0 |
| chainguard | hadoop-fips-3.5 | 0, 0 |
| Red Hat | Red Hat Data Grid 8.6.2 | codec-redis, codec-redis, codec-redis |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | 0:1.10.0-46.Final_redhat_00044.1.el7eap, 0:1.10.0-46.Final_redhat_00044.1.el7eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | 0:2.2.40-2.SP3_redhat_00001.1.el7eap, 0:2.2.40-2.SP3_redhat_00001.1.el7eap |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | 0:4.1.135-1.Final_redhat_00001.1.el7eap, 0:4.1.135-1.Final_redhat_00001.1.el7eap |
| Maven | io.netty:netty-codec-redis | 0 |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | 0:2.5.5-30.SP12_redhat_00020.1.el7eap, 0:2.5.5-30.SP12_redhat_00020.1.el7eap |
| chainguard | management-api-for-apache-cassandra-5.0 | 0, 0, 0 |
| chainguard | seata | 0, 0, 0 |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | 0:1.5.26-2.Final_redhat_00001.1.el7eap, 0:1.5.26-2.Final_redhat_00001.1.el7eap |
…and 26 more
Timeline
- Jun 12, 2026 CVE Published
- Jun 13, 2026 Coalition ESS Score
- Jun 15, 2026 Security Advisory
- Jul 9, 2026 EPSS Score
- Jul 9, 2026 Distribution Patch
- Jul 9, 2026 Security Advisory
- Jul 20, 2026 Distribution Patch
- Jul 20, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
- Aug 12, 2026 Distribution Patch
References
- https://github.com/netty/netty/security/advisories/GHSA-5w86-c3rq-vjj7 x_refsource_CONFIRM
- https://github.com/netty/netty/releases/tag/netty-4.1.135.Final x_refsource_MISC
- https://github.com/netty/netty/releases/tag/netty-4.2.15.Final x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2026-50011 vdb
- RHBZ#2488413 issue
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50011.json url
- https://access.redhat.com/errata/RHSA-2026:53644 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:41951 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:53806 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:50085 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:37390 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-50011 advisory
- https://github.com/advisories/GHSA-5w86-c3rq-vjj7 advisory