Signed to Unsigned Conversion Error in Netty - #VU148885

 

Signed to Unsigned Conversion Error in Netty - #VU148885

Published: September 10, 2026


Vulnerability identifier: #VU148885
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-195
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose response data to other clients.

The vulnerability exists due to a signed to unsigned conversion error in the memcache binary protocol codec when processing crafted memcache responses. A remote attacker can send a specially crafted memcache response to disclose response data to other clients.

The issue can desynchronize frame boundaries in proxy or cache scenarios.


Affected software

Netty

Remediation

Install security update from vendor's website.

Netty - addressed in versions 4.1.138, 4.2.18

External References

Related Security Bulletins