Feed/CVE-2026-45674
CVE-2026-45674HIGHCVSS 8.7

CVE-2026-45674

Published Jun 12, 2026·Updated Aug 20, 2026

NVD Description

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

Affected Packages (1)

io.netty:netty-resolver-dnsMAVEN
From 4.2.0.Final
Fixed in = 4.2.14.Final

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free