PT-2026-47610 · Netty · Netty

·

CVE-2026-45674

·

Published

2026-06-08

·

Updated

2026-07-22

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.135.Final Netty versions prior to 4.2.15.Final
Description Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. In the buildAliasMap() function within io.netty.resolver.dns.DnsResolveContext, the resolver processes the ANSWER section of a DNS response and caches all found CNAME records without verification. This can lead to DNS Cache Poisoning (Bailiwick Bypass), where an attacker provides unauthorized DNS data for a domain they do not control.
Recommendations Update to version 4.1.135.Final Update to version 4.2.15.Final

Exploit

Fix

Insufficient Verification of Data Authenticity

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BK55944
CLEANSTART-2026-FV79231
CLEANSTART-2026-KL03760
CLEANSTART-2026-LB41442
CLEANSTART-2026-NE94194
CLEANSTART-2026-RS65756
CLEANSTART-2026-SH44648
CLEANSTART-2026-YY96069
CVE-2026-45674
GHSA-676X-F7GG-47VC
OPENSUSE-SU-2026:11033-1
RHSA-2026:53644
SUSE-SU-2026:2802-1

Affected Products

Netty