What is CVE-2026-56818?
CVE-2026-56818 affects the Netty framework where the RedisArrayAggregator codec fails to clear partial aggregate state when the 'maxElement' limit is exceeded, although it does so for 'maxNestedArrayDepth'. This can lead to memory leaks or resource exhaustion. Users should upgrade to Netty 4.1.136.Final or 4.2.16.Final.
Azərbaycanca: Netty framework-də CVE-2026-56818, RedisArrayAggregator komponentində 'maxNestedArrayDepth' həddi aşıldıqda saxlanılan qismən aqreqat vəziyyətinin düzgün təmizlənməməsi zəifliyidir. Bu, 'maxElement' həddi keçildikdə yaddaş sızmasına və ya resursların tükənməsinə səbəb ola bilər. Netty 4.1.136.Final və ya 4.2.16.Final versiyalarına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which component of the Netty framework does CVE-2026-56818 affect?
CVE-2026-56818 affects the RedisArrayAggregator codec component in the Netty framework.
To which versions should Netty be upgraded to fix this vulnerability?
Users should upgrade to Netty 4.1.136.Final or 4.2.16.Final.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.