CVE-2026-93561
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Summary
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads keyLength and extrasLength as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can lead to frame desynchronization and response smuggling, where one client's data may be inadvertently exposed to another client's response stream in proxy or cache environments.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-1035: CWE-1035
Workarounds
See https://github.com/netty/netty/security/advisories/GHSA-wxrh-4rgq-pjcg for fixed versions and remediation guidance.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
Additional References
References
- https://access.redhat.com/security/cve/CVE-2026-93561
- https://bugzilla.redhat.com/show_bug.cgi?id=2536949
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.