6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether io.netty:netty-codec-redis is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-48006
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
HIGH 7.5
CVE-2026-44890
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
HIGH 7.5
CVE-2026-44250
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
MEDIUM 6.5
CVE-2026-56818
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
HIGH 7.5
CVE-2026-50011
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
MEDIUM 6.8
CVE-2026-42586
Netty Redis Codec Encoder has a CRLF Injection Issue
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes