CVE-2026-45673Medium· 6.8▾ SunlitA flaw was found in Netty's DNS resolver component. This vulnerability arises from the use of a predictable pseudo-random number generator (PRNG) for DNS transaction IDs and a static User Datagram Protocol (UDP) source port. This combinati…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
Last analysed / modified upstream
A flaw was found in Netty's DNS resolver component. This vulnerability arises from the use of a predictable pseudo-random number generator (PRNG) for DNS transaction IDs and a static User Datagram Protocol (UDP) source port. This combination significantly reduces the randomness of DNS queries, making it easier for a remote attacker to perform DNS Cache Poisoning, also known as a Kaminsky attack. Successful exploitation could allow an attacker to redirect network traffic to malicious servers.
netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs — rated Moderate by Red Hat. Released 2026-06-12, updated 2026-09-07.
Affected:
Fixed:
No fix planned:
Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:50085 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:26018 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:26017
Workarounds / mitigations:
Affected packages:
io.netty:netty-resolver-dns >= 4.2.0.Final, <= 4.2.14.Finalio.netty:netty-resolver-dns <= 4.1.134.FinalPatched in:
io.netty:netty-resolver-dns 4.2.15.Finalio.netty:netty-resolver-dns 4.1.135.FinalConnected by shared product, vendor, weakness, or advisory.
CVE-2026-47244Medium· 5.3netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams (CVE-2026-47244)
CVE-2026-50020Medium· 5.3netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder (CVE-2026-50020)
CVE-2026-50560Medium· 5.3netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling (CVE-2026-50560)
CVE-2026-55851High· 7.5io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851)
CVE-2026-73508Medium· 5.3Netty is an asynchronous, event-driven network application framework
CVE-2026-93433Medium· 5.5A flaw was found in libstoragemgmt