netty-codec-memcache is vulnerable to Response Smuggling
75
High Risk
The binary Memcache codec reads the keyLength and extrasLength fields using signed Java types although the protocol defines them as unsigned. Crafted values are misinterpreted, desynchronizing frame boundaries in the decoded stream. In proxy or shared-cache deployments this leads to response smuggling, where one client's data bleeds into another client's response. The fix reads these length fields as unsigned.
You are affected if you are using a version that falls within the vulnerable range and your application uses the binary Memcache codec with untrusted or shared cache infrastructure.
netty-codec-memcache is vulnerable to Response Smuggling in versions 4.1.0.Final - 4.1.137.Final and 4.2.0.Final - 4.2.17.Final.
Upgrade the io.netty:netty-codec-memcache library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.