LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-48006

netty · netty

Published
CVSS7.5
Severityhigh
WeaknessCWE-401
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes. The handler retains child messages in per-handler state (`depths` field) but defines no `channelInactive`, `handlerRemoved`, or `exceptionCaught` method to release them when the pipeline tears down. Because the leaked buffers are slices of `PooledByteBufAllocator` chunks, they prevent those chunks from being returned to the JVM-wide direct-memory pool. Repeated connection churn by any network pee

References

← Back to the CVE Tracker

Our coverage of CVE-2026-48006

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-48006.