- Description
- Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
- Source
- security-advisories@github.com
- NVD status
- Modified
- Products
- netty
CVSS 3.1
- Type
- Primary
- Base score
- 10
- Impact score
- 5.8
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- Severity
- CRITICAL
- Hype score
- Not currently trending
π¨ CRITICAL: Netty DNS Resolver Flaws β Cache Poisoning Vulnerabilities CVE-2026-45673 (CVSS 6.8), CVE-2026-45674 (CVSS 8.7), CVE-2026-47691 (CVSS 8.7) π https://t.co/72OWRZSG5I #CyberSecurity #ThreatIntel #infosec #Netty #Java
@ThreatAft
20 Jun 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Urgent! Netty DNS cache poisoning (CVE-2026-45674/45673) & ClipBucket SQLi (CVE-2026-49482) reported within the last hour. These critical vulns enable traffic interception & data exfiltration. High risk to privacy/integrity. Patch now! #Cybersecurity #NetworkSecurity #Zer
@YourAnon_irc
12 Jun 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3097D962-A32D-4467-AAE7-F4CBA3A349D2",
"versionEndExcluding": "4.1.135",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*",
"matchCriteriaId": "413D4611-A46C-4BE4-AB2F-D86282F65984",
"versionEndExcluding": "4.2.15",
"versionStartIncluding": "4.2.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]