THREAT OPS › Threat News › [NVD] CVE-2026-56818 (MEDIUM 6.5) — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when th
[NVD] CVE-2026-56818 (MEDIUM 6.5) — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when th
CVE-2026-56818 CVSS: 6.5 MEDIUM Published: 2026-08-07T18:17:19.100
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when the sibling maxElements limit is exceeded. A peer can
Indicators of compromise
- CVE-2026-56818cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-56818