Netty是Netty社区的一款非阻塞I/O客户端-服务器框架,它主要用于开发Java网络应用程序,如协议服务器和客户端等。 Netty 4.1.135.Final之前版本和4.2.15.Final之前版本存在资源管理错误漏洞,该漏洞源于跨多个连接发送不含 的特制Redis有效载荷,可能导致服务器直接内存池耗尽,从而造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44249 | 8.1 HIGH | Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking |
| CVE-2026-44250 | 7.5 HIGH | Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays |
No comments yet