CVE-2026-42586Netty · Netty
Vulnerability data via NVD (ingested)
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-42586product:"Netty Netty"http.html:"Netty"More intel sources (5)
vuln:CVE-2026-42586vulnerabilities.cve_id: CVE-2026-42586CVE-2026-42586CVE-2026-42586"CVE-2026-42586" exploit -site:nvd.nist.gov