CVE-2026-45674

Published Jun 12, 2026

Last updated 5 days ago

CVSS high 8.7
Port (53)

Overview

Description
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Source
security-advisories@github.com
NVD status
Modified
Products
netty

Risk scores

CVSS 3.1

Type
Primary
Base score
10
Impact score
5.8
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-345
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-346

Social media

Hype score
Not currently trending

Configurations