This is a mature, actively released, stable Maven library with 166 releases over roughly 10 years, 21 releases in the last 12 months, no registry deprecation, a focused runtime dependency profile, and Maven PGP build provenance. The main concerns are that no license declaration or license file was found and the published artifact contains no README, tests, or changelog; repository-backed maintenance signals were not available, limiting transparency and confidence. It is generally usable as a dependency, but license clarification and independent review of the upstream project are advisable.
72%
Total Score
100
80
100
100
Neither a declared license nor a license file was found. This is a material legal and transparency concern for adopting the dependency and should be resolved before use in projects with licensing requirements.
The artifact has no README, tests, or changelog, and no repository-side compensation was collected. Missing consumer documentation and packaged tests reduce transparency and maintenance confidence, even though such files are often kept outside a compiled library artifact.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-198062 New netty-codec-redis is vulnerable to Denial of Service (DoS) in versions 4.1.135.Final - 4.1.137.Final and 4.2.15.Final - 4.2.17.Final. | 4.1.135.Final - 4.1.137.Final4.2.15.Final - 4.2.17.Final | High |
CVE-2026-56818 io.netty:netty-codec-redis is vulnerable to Missing Release of Memory after Effective Lifetime in versions 0.0.0 - 4.1.136.Final and 4.2.0-Final - 4.2.16.Final. | 0.0.0 - 4.1.136.Final4.2.0-Final - 4.2.16.Final | Medium |
CVE-2026-50011 io.netty:netty-codec-redis is vulnerable to Uncontrolled Resource Consumption in versions 4.2.0.Final - 4.2.14.Final and 0.0.0 - 4.1.134.Final. | 0.0.0 - 4.1.134.Final4.2.0.Final - 4.2.14.Final | High |
CVE-2026-48006 io.netty:netty-codec-redis is vulnerable to Missing Release of Memory after Effective Lifetime in versions 4.2.0.Final - 4.2.14.Final and 0.0.0 - 4.1.134.Final. | 0.0.0 - 4.1.134.Final4.2.0.Final - 4.2.14.Final | High |
CVE-2026-44890 io.netty:netty-codec-redis is vulnerable to Uncontrolled Resource Consumption in versions 4.2.0.Final - 4.2.14.Final and 0.0.0 - 4.1.134.Final. | 0.0.0 - 4.1.134.Final4.2.0.Final - 4.2.14.Final | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
${project.groupId}:netty-common Version 4.2.18.Final | — | — |
${project.groupId}:netty-buffer Version 4.2.18.Final | — | — |
${project.groupId}:netty-transport Version 4.2.18.Final | — | — |
${project.groupId}:netty-codec-base Version 4.2.18.Final | — | — |
org.reflections:reflections Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.