Impact
RedisArrayAggregator in the Netty Redis codec adds limits to prevent resource exhaustion but still preallocates memory eagerly. A malicious actor can send thousands of nested RESP array headers with large length values; the allocator creates an ArrayList with the specified initial capacity even before child elements are added. With the default limits of 1,024 nested arrays and a header length of one million, an attacker can reserve over a billion slot allocations from only a few kilobytes of input, exhausting host memory and causing the application to become unresponsive. The flaw is an instance of unchecked resource consumption (CWE-770).
Affected Systems
Products affected by this issue are the Red Hat build-of-Apache Camel for Spring Boot 4, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, and Red Hat Single Sign-On 7. Any installation that incorporates the vulnerable netty-codec-redis library, regardless of the application domain, is at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score indicates a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote: an adversary must be able to send crafted RESP commands to the exposed Redis endpoint. Because the bug is triggered by large array headers, basic authentication or network restrictions do not mitigate it unless additional controls are applied. Once exploited, the service can experience memory exhaustion, leading to denial of service.
OpenCVE Enrichment