Signed to Unsigned Conversion Error in Netty - #VU148885
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose response data to other clients.
The vulnerability exists due to a signed to unsigned conversion error in the memcache binary protocol codec when processing crafted memcache responses. A remote attacker can send a specially crafted memcache response to disclose response data to other clients.
The issue can desynchronize frame boundaries in proxy or cache scenarios.