Description
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can lead to frame desynchronization and response smuggling, where one client's data may be inadvertently exposed to another client's response stream in proxy or cache environments.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential response manipulation or data tampering
Action: Patch Now
AI Analysis

Impact

A signed/unsigned type mismatch in the Netty Memcache binary codec leads to frame desynchronization, allowing a crafted memcache request to be interpreted incorrectly and to cause response smuggling. The flaw is a mismatched signedness handling weakness (CWE‑1035). The CVE description does not specify downstream consequences beyond response manipulation.

Affected Systems

The vulnerability affects Red Hat’s distribution of the Netty Memcache codec bundled with Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign‑On 7, and the Red Hat build of Apache Camel for Spring Boot 4. Specific affected product versions are not listed in the available data, so any installation that includes the vulnerable Netty memcache codec in these distributions may be impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1% and the fact that the vulnerability is not listed in the CISA KEV catalog suggest that its exploitation probability is low and no widespread attacks have been observed. Based on the description, it can be inferred that the attack vector involves sending memcached binary protocol traffic to the application over the network. The CVE does not state whether automated exploitation tools exist, so manual crafting of a malformed request may be required, but this is also an inference. Overall, the risk is moderate, and patching is recommended.

Generated by OpenCVE AI on September 19, 2026 at 18:13 UTC.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-wxrh-4rgq-pjcg for fixed versions and remediation guidance.


OpenCVE Recommended Actions

  • Apply the vendor patch that updates the Netty Memcache binary codec to a fixed version as listed in the provided workaround link.
  • If an update cannot be applied immediately, disable or replace the memcache binary protocol usage in the affected applications, or reconfigure the services to use the memcache text protocol.
  • Monitor application logs for errors related to memcache frame desynchronization or unexpected response lengths, which may indicate attempted exploitation.

Generated by OpenCVE AI on September 19, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3
Redhat rsingle Sign-on
Vendors & Products Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3
Redhat rsingle Sign-on

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can lead to frame desynchronization and response smuggling, where one client's data may be inadvertently exposed to another client's response stream in proxy or cache environments.
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Netty: netty-codec-memcache: io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling
Title Netty: netty-codec-memcache: io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling
First Time appeared Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
Weaknesses CWE-1035
CPEs cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
References

Subscriptions

Io.netty Netty-codec-http
Redhat Build Of Apache Camel For Spring Boot Camel Spring Boot Jboss Enterprise Application Platform Jboss Fuse Quay 3 Red Hat Single Sign On Rsingle Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T08:28:53.009Z

Reserved: 2026-09-18T09:47:37.249Z

Link: CVE-2026-93561

cve-icon Vulnrichment

Updated: 2026-09-18T14:54:26.760Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T11:17:21.650

Modified: 2026-09-25T09:17:07.287

Link: CVE-2026-93561

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:44:07Z

Links: CVE-2026-93561 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:56Z

Weaknesses