PT-2026-38372 · Netty+4 · Netty+4

CVE-2026-42579

·

Published

2026-05-05

·

Updated

2026-08-12

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.133.Final Netty versions prior to 4.2.13.Final
Description Netty's DNS codec fails to enforce RFC 1035 domain name constraints during encoding and decoding, creating a bidirectional attack surface. In the encoder, the encodeDomainName() function in io.netty.handler.codec.dns.DnsCodecUtil allows null bytes, labels exceeding 63 bytes, and total domain names exceeding 255 bytes. This can lead to DNS cache poisoning, domain validation bypass, and parser confusion where overlength labels are misinterpreted as compression pointers. Additionally, empty labels cause the domain name to be silently truncated. In the decoder, the decodeDomainName() function in io.netty.handler.codec.dns.DnsCodecUtil does not validate label or total name lengths, allowing malicious DNS responses to trigger unbounded memory allocation via StringBuilder growth, potentially leading to a denial of service.
Recommendations Update to version 4.1.133.Final or later. Update to version 4.2.13.Final or later. As a temporary workaround, restrict the use of the io.netty.handler.codec.dns.DnsCodecUtil module or validate user-influenced hostnames before passing them to the DNS encoder.

Exploit

Fix

DoS

RCE

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08933
CLEANSTART-2026-BK55944
CLEANSTART-2026-BO52019
CLEANSTART-2026-CP46043
CLEANSTART-2026-DD05788
CLEANSTART-2026-DT81884
CLEANSTART-2026-EG39405
CLEANSTART-2026-FV79231
CLEANSTART-2026-FX60287
CLEANSTART-2026-FZ22182
CLEANSTART-2026-GX01236
CLEANSTART-2026-GX44743
CLEANSTART-2026-IY44515
CLEANSTART-2026-KL03760
CLEANSTART-2026-LB41442
CLEANSTART-2026-LE11246
CLEANSTART-2026-MT41286
CLEANSTART-2026-MX76059
CLEANSTART-2026-NE94194
CLEANSTART-2026-PO27799
CLEANSTART-2026-RN56220
CLEANSTART-2026-RS65756
CLEANSTART-2026-RU36468
CLEANSTART-2026-SH44648
CLEANSTART-2026-VJ37814
CLEANSTART-2026-VP53607
CLEANSTART-2026-WK99982
CLEANSTART-2026-YY96069
CVE-2026-42579
GHSA-CM33-6792-R9FM
OPENSUSE-SU-2026:10795-1
RHSA-2026:53644
SUSE-SU-2026:2308-1
USN-8401-1

Affected Products

Confluence
Linuxmint
Netty
Red Os
Ubuntu