CVE-2026-93561: Red Hat Build Of Apache Camel For Spring Boot 4
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can lead to frame desynchronization and response smuggling, where one client's data may be inadvertently exposed to another client's response stream in proxy or cache environments.
Affected products
- Red Hat Red Hat Build Of Apache Camel For Spring Boot 4
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat Single Sign-On 7
Published 2026-09-18. Last modified 2026-09-25.