Description
Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling
Published: 2026-09-18
Score: 6.5 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-wxrh-4rgq-pjcg for fixed versions and remediation guidance.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Netty: netty-codec-memcache: io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling
Title Netty: netty-codec-memcache: io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling
First Time appeared Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
Weaknesses CWE-1035
CPEs cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
References

Subscriptions

Redhat Camel Spring Boot Jboss Enterprise Application Platform Jboss Fuse Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-18T14:54:30.400Z

Reserved: 2026-09-18T09:47:37.249Z

Link: CVE-2026-93561

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T11:17:21.650

Modified: 2026-09-18T14:19:08.343

Link: CVE-2026-93561

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:44:07Z

Links: CVE-2026-93561 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses