CVE-2026-45674

HIGH

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

Title source: cna
STIX 2.1

Description

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

References (3)

Core 3

Scores

CVSS v3 8.7
EPSS 0.0024
EPSS Percentile 14.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-345
Status published
Products (5)
io.netty/netty-resolver-dns 0 - 4.1.135.FinalMaven
io.netty/netty-resolver-dns 4.2.0.Final - 4.2.15.FinalMaven
netty/netty < 4.1.135
netty/netty < 4.1.135.Final
netty/netty >= 4.2.0.Final, < 4.2.15.Final
Published Jun 12, 2026
Tracked Since Jun 12, 2026