Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3166 articles · 183331 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2026-44249EXPLOITEDPATCHED
netty · netty

Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking

Description

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

Affected Products

VendorProductVersions
nettynetty>= 4.2.0.Final, < 4.2.15.Final, < 4.1.135.Final

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
atlassiancruciblecert_advisory90%
atlassianbitbucketcert_advisory90%
atlassianjiracert_advisory90%
atlassianbamboocert_advisory90%
atlassianfisheyecert_advisory90%

References

  • https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86(x_refsource_CONFIRM)
  • https://github.com/netty/netty/releases/tag/netty-4.1.135.Final(x_refsource_MISC)
  • https://github.com/netty/netty/releases/tag/netty-4.2.15.Final(x_refsource_MISC)

Related News (3 articles)

Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (24 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories12d ago
[NEU] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB52d ago
CVE-2026-44249 | Netty prior 4.1.135.Final/4.2.15.Final IpSubnetFilterRule.compareTo access control (GHSA-3qp7-7mw8-wx86)
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
io.netty:netty-handler@4.2.15.Finalio.netty:netty-handler@4.1.135.Final
CWECWE-284, CWE-697
PublishedJun 8, 2026
Last enriched52d agov2
Tags
GHSA-3qp7-7mw8-wx86maven
Trending Score14
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-42581EXP
Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
Trending: 71
NONECVE-2026-42578EXP
Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
Trending: 34
HIGHCVE-2026-42583EXP
Netty: Lz4FrameDecoder resource exhaustion
Trending: 26
HIGHCVE-2026-42587
Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
Trending: 17
HIGHCVE-2026-45674EXP
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
Trending: 14

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 8, 2026
Discovered by ZDM
Jun 8, 2026
Updated: description, severity, activelyExploited
Jun 12, 2026
Actively Exploited
Aug 3, 2026
Patch Available
Aug 3, 2026

Version History

v2
Last enriched 52d ago
v2Tier C52d ago

Updated severity to CRITICAL, changed exploit availability to false, and provided a new description with details about CVE-2026-44249.

descriptionseverityactivelyExploited
via VulDB
v155d ago

Initial creation