A flaw was found in io.netty/netty-codec-memcache. (CVE-2026-93561)
A vulnerability in io.netty/netty-codec-memcache allows a malicious Memcache server to exploit a protocol parsing flaw. The codec incorrectly interprets keyLength and extrasLength fields as signed instead of unsigned, causing frame desynchronization and response smuggling. This can lead to one client's data being exposed to another in proxy or cache environments. The issue affects multiple specific versions of netty. The CVSS score is 6.5 (medium severity).
AI Analysis
Technical Summary
The Memcache binary protocol codec in io.netty/netty-codec-memcache incorrectly reads the keyLength and extrasLength fields as signed Java types rather than unsigned as required by the protocol specification. A malicious Memcache server can exploit this mismatch by sending specially crafted responses that cause frame desynchronization and response smuggling. This flaw can result in cross-client data exposure in proxy or cache scenarios. The vulnerability is identified as CVE-2026-93561 with a CVSS 3.1 base score of 6.5, indicating medium severity. Multiple specific netty versions are affected as listed.
Potential Impact
Exploitation of this vulnerability can lead to frame desynchronization and response smuggling, potentially causing data from one client to be exposed to another client's response stream in proxy or cache environments. This compromises confidentiality but does not affect availability. No known exploits in the wild have been reported.
Mitigation Recommendations
No vendor advisory or patch information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid using affected versions in environments where untrusted Memcache servers are present or where proxy/cache response isolation is critical.
A flaw was found in io.netty/netty-codec-memcache. (CVE-2026-93561)
Description
A vulnerability in io.netty/netty-codec-memcache allows a malicious Memcache server to exploit a protocol parsing flaw. The codec incorrectly interprets keyLength and extrasLength fields as signed instead of unsigned, causing frame desynchronization and response smuggling. This can lead to one client's data being exposed to another in proxy or cache environments. The issue affects multiple specific versions of netty. The CVSS score is 6.5 (medium severity).
CVSS v3.1
Score 6.5medium
Affected software
pkg:deb/ubuntu/netty?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/netty?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/netty?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/netty?arch=source&distro=esm-apps/resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Memcache binary protocol codec in io.netty/netty-codec-memcache incorrectly reads the keyLength and extrasLength fields as signed Java types rather than unsigned as required by the protocol specification. A malicious Memcache server can exploit this mismatch by sending specially crafted responses that cause frame desynchronization and response smuggling. This flaw can result in cross-client data exposure in proxy or cache scenarios. The vulnerability is identified as CVE-2026-93561 with a CVSS 3.1 base score of 6.5, indicating medium severity. Multiple specific netty versions are affected as listed.
Potential Impact
Exploitation of this vulnerability can lead to frame desynchronization and response smuggling, potentially causing data from one client to be exposed to another client's response stream in proxy or cache environments. This compromises confidentiality but does not affect availability. No known exploits in the wild have been reported.
Mitigation Recommendations
No vendor advisory or patch information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid using affected versions in environments where untrusted Memcache servers are present or where proxy/cache response isolation is critical.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-93561
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:Pro:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be2ef7a7c54106eeec25
Added to database: 09/24/2026, 06:07:42 UTC
Last enriched: 09/24/2026, 06:29:39 UTC
Last updated: 09/25/2026, 03:47:33 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.