PT-2026-47600 · Unknown+1 · Netty-Handler+1

·

CVE-2026-44249

·

Published

2026-06-08

·

Updated

2026-09-01

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions netty-handler versions prior to 4.1.135.Final netty-handler versions prior to 4.2.15.Final
Description An incorrect masking operation in the compareTo() function of the IpSubnetFilterRule class allows an attacker to bypass IPv6 subnet rules. Specifically, the io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress) method performs a bitwise AND between the incoming IP address and the configured networkAddress instead of the subnetMask, enabling valid public IP addresses to bypass access controls.
Recommendations Update to version 4.1.135.Final. Update to version 4.2.15.Final.

Exploit

Fix

DoS

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BK55944
CLEANSTART-2026-FV79231
CLEANSTART-2026-KL03760
CLEANSTART-2026-LB41442
CLEANSTART-2026-NE94194
CLEANSTART-2026-NW12954
CLEANSTART-2026-RS65756
CLEANSTART-2026-SH44648
CLEANSTART-2026-YY96069
CVE-2026-44249
GHSA-3QP7-7MW8-WX86
OPENSUSE-SU-2026:11033-1
RHSA-2026:49700
RHSA-2026:53644
SUSE-SU-2026:2802-1

Affected Products

Red Os
Netty-Handler