Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3198 articles · 183323 vulns · 37/41 feeds (7d)
← Back to list
8.7
CVE-2026-45674EXPLOITEDPATCHED
netty · netty

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

Description

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

Affected Products

VendorProductVersions
nettynettymaven/io.netty:netty-resolver-dns: >= 4.2.0.Final, <= 4.2.14.Final, maven/io.netty:netty-resolver-dns: <= 4.1.134.Final

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mavenio.netty:netty-resolver-dnsGHSA85%

References

  • https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc(x_refsource_CONFIRM)
  • https://github.com/netty/netty/releases/tag/netty-4.1.135.Final(x_refsource_MISC)
  • https://github.com/netty/netty/releases/tag/netty-4.2.15.Final(x_refsource_MISC)

Related News (3 articles)

Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (24 juillet 2026)
→ No new info (linked only)
Tier C
VulDB52d ago
CVE-2026-45674 | Netty prior 4.1.135.Final/4.2.15.Final DNS Response data authenticity
→ No new info (linked only)
Tier B
BSI Advisories56d ago
[NEU] [hoch] Netty: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.18.7 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
io.netty:netty-resolver-dns@4.2.15.Finalio.netty:netty-resolver-dns@4.1.135.Final
CWECWE-345, CWE-346
PublishedJun 12, 2026
Last enriched51d agov2
Trending Score14
Source articles3
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-42581EXP
Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
Trending: 71
NONECVE-2026-42578EXP
Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
Trending: 34
HIGHCVE-2026-42583EXP
Netty: Lz4FrameDecoder resource exhaustion
Trending: 26
HIGHCVE-2026-42587
Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
Trending: 17
HIGHCVE-2026-44249EXP
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
Trending: 14

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 12, 2026
Discovered by ZDM
Jun 12, 2026
Updated: description, activelyExploited
Jun 12, 2026
Actively Exploited
Jul 30, 2026
Patch Available
Jul 30, 2026

Version History

v2
Last enriched 51d ago
v2Tier C51d ago

Updated description with new details about the DNS Response Handler and marked the vulnerability as actively exploited.

descriptionactivelyExploited
via VulDB
v152d ago

Initial creation