10

CVE-2026-45674

Medienbericht

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netty ≫ Netty Version < 4.1.135
Netty ≫ Netty Version >= 4.2.0 < 4.2.15
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.162
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
security-advisories@github.com 8.7 2.2 5.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 8.7 2.2 5.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
18.09.2026 14:04
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
27.08.2026 09:47
https://bugzilla.redhat.com/show_bug.cgi?id=2488400
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45674.json
https://access.redhat.com/errata/RHSA-2026:34608
https://access.redhat.com/errata/RHSA-2026:26586
https://github.com/netty/netty/releases/tag/netty-4.1.135.Final
Release Notes
https://github.com/netty/netty/releases/tag/netty-4.2.15.Final
Release Notes
https://access.redhat.com/errata/RHSA-2026:26017
https://access.redhat.com/errata/RHSA-2026:26018
https://access.redhat.com/errata/RHSA-2026:37390
https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-45674
https://access.redhat.com/errata/RHSA-2026:41951
https://access.redhat.com/errata/RHSA-2026:48151
https://access.redhat.com/errata/RHSA-2026:49700
https://access.redhat.com/errata/RHSA-2026:49701
https://access.redhat.com/errata/RHSA-2026:50085
https://access.redhat.com/errata/RHSA-2026:53644
https://access.redhat.com/errata/RHSA-2026:54435
https://access.redhat.com/errata/RHSA-2026:62260
https://access.redhat.com/errata/RHSA-2026:65126
https://access.redhat.com/errata/RHSA-2026:53645
https://access.redhat.com/errata/RHSA-2026:53646