Description
A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly preallocate a large amount of heap memory, leading to heap memory exhaustion and a Denial of Service (DoS) for applications using `RedisDecoder` with `RedisArrayAggregator` on untrusted traffic.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Memory Exhaustion
Action: Immediate Patch
AI Analysis

Impact

RedisArrayAggregator in the Netty Redis codec adds limits to prevent resource exhaustion but still preallocates memory eagerly. A malicious actor can send thousands of nested RESP array headers with large length values; the allocator creates an ArrayList with the specified initial capacity even before child elements are added. With the default limits of 1,024 nested arrays and a header length of one million, an attacker can reserve over a billion slot allocations from only a few kilobytes of input, exhausting host memory and causing the application to become unresponsive. The flaw is an instance of unchecked resource consumption (CWE-770).

Affected Systems

Products affected by this issue are the Red Hat build-of-Apache Camel for Spring Boot 4, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, and Red Hat Single Sign-On 7. Any installation that incorporates the vulnerable netty-codec-redis library, regardless of the application domain, is at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score indicates a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote: an adversary must be able to send crafted RESP commands to the exposed Redis endpoint. Because the bug is triggered by large array headers, basic authentication or network restrictions do not mitigate it unless additional controls are applied. Once exploited, the service can experience memory exhaustion, leading to denial of service.

Generated by OpenCVE AI on September 19, 2026 at 16:26 UTC.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-r4xx-7fpg-j8xg for fixed versions and remediation guidance.


OpenCVE Recommended Actions

  • Upgrade the Netty library to the fixed version referenced in the GitHub advisory, or apply the corresponding Red Hat package update that replaces netty-codec-redis in Fuse 7, JBoss EAP 7, Camel 4, and Single Sign-On 7.
  • If an immediate update is not feasible, restrict network access to the Redis endpoint to trusted hosts and enforce authentication so that only authorized clients can send commands.
  • As a temporary mitigation, disable or limit nested RESP array usage in the application configuration where possible; consult the GitHub advisory for earliest non-patch fallback.
  • Monitor host memory and application performance for signs of exhaustion and plan a rapid deployment of the official patch.

Generated by OpenCVE AI on September 19, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3
Redhat single Sign-on
Vendors & Products Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3
Redhat single Sign-on

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description ## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array header creates `new ArrayList<RedisMessage>(length)` before any child element exists. With the default constructor, an attacker can send nested array headers with length `1,000,000` until the default nesting limit of `1024` is reached. This can reserve up to `1,024,000,000` child slots from roughly 12 KB of RESP input. This is backing capacity, not logical list size: `ArrayList(int)` constructs an empty list with the specified initial capacity. ## Technical Details Current `decodeRedisArrayHeader(...)` checks the two limits independently: ```java if (header.length() > maxElements) { throw new CodecException("this codec doesn't support longer length than " + maxElements); } if (depths.size() >= maxNestedArrayDepth) { releaseAndClearDepths(); throw new CodecException("max nested array depth exceeded: " + maxNestedArrayDepth); } depths.push(new AggregateState((int) header.length())); ``` `AggregateState` i A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly preallocate a large amount of heap memory, leading to heap memory exhaustion and a Denial of Service (DoS) for applications using `RedisDecoder` with `RedisArrayAggregator` on untrusted traffic.
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Netty: netty-codec-redis: io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patched preallocation limits Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patched preallocation limits

Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Fri, 18 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description ## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array header creates `new ArrayList<RedisMessage>(length)` before any child element exists. With the default constructor, an attacker can send nested array headers with length `1,000,000` until the default nesting limit of `1024` is reached. This can reserve up to `1,024,000,000` child slots from roughly 12 KB of RESP input. This is backing capacity, not logical list size: `ArrayList(int)` constructs an empty list with the specified initial capacity. ## Technical Details Current `decodeRedisArrayHeader(...)` checks the two limits independently: ```java if (header.length() > maxElements) { throw new CodecException("this codec doesn't support longer length than " + maxElements); } if (depths.size() >= maxNestedArrayDepth) { releaseAndClearDepths(); throw new CodecException("max nested array depth exceeded: " + maxNestedArrayDepth); } depths.push(new AggregateState((int) header.length())); ``` `AggregateState` i
Title Netty: netty-codec-redis: io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patched preallocation limits
First Time appeared Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
Weaknesses CWE-770
CPEs cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
References

Subscriptions

Io.netty Netty-codec-http
Redhat Build Of Apache Camel For Spring Boot Camel Spring Boot Jboss Enterprise Application Platform Jboss Fuse Quay 3 Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T08:29:02.541Z

Reserved: 2026-09-18T10:29:10.414Z

Link: CVE-2026-93572

cve-icon Vulnrichment

Updated: 2026-09-18T14:40:18.566Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T11:17:21.900

Modified: 2026-09-25T09:17:07.530

Link: CVE-2026-93572

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:52:10Z

Links: CVE-2026-93572 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:52Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling