Impact
A signed/unsigned type mismatch in the Netty Memcache binary codec leads to frame desynchronization, allowing a crafted memcache request to be interpreted incorrectly and to cause response smuggling. The flaw is a mismatched signedness handling weakness (CWE‑1035). The CVE description does not specify downstream consequences beyond response manipulation.
Affected Systems
The vulnerability affects Red Hat’s distribution of the Netty Memcache codec bundled with Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign‑On 7, and the Red Hat build of Apache Camel for Spring Boot 4. Specific affected product versions are not listed in the available data, so any installation that includes the vulnerable Netty memcache codec in these distributions may be impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1% and the fact that the vulnerability is not listed in the CISA KEV catalog suggest that its exploitation probability is low and no widespread attacks have been observed. Based on the description, it can be inferred that the attack vector involves sending memcached binary protocol traffic to the application over the network. The CVE does not state whether automated exploitation tools exist, so manual crafting of a malformed request may be required, but this is also an inference. Overall, the risk is moderate, and patching is recommended.
OpenCVE Enrichment