THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-56818 (MEDIUM 6.5) — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when th

[NVD] CVE-2026-56818 (MEDIUM 6.5) — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when th

mednvdPublished 2026-08-07

CVE-2026-56818 CVSS: 6.5 MEDIUM Published: 2026-08-07T18:17:19.100

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when the sibling maxElements limit is exceeded. A peer can

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-56818