CVE-2026-45674High· 8.7▾ MidnightPoC availableNetty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 47.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
1 GitHub repo
Last analysed / modified upstream
0.2% → 0.3%
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
netty < 4.1.135netty >= 4.2.0, < 4.2.15Upgrade past the affected range:
netty 4.2.15Affected packages:
io.netty:netty-resolver-dns >= 4.2.0.Final, <= 4.2.14.Finalio.netty:netty-resolver-dns <= 4.1.134.FinalPatched in:
io.netty:netty-resolver-dns 4.2.15.Finalio.netty:netty-resolver-dns 4.1.135.FinalSource: https://github.com/advisories/GHSA-676x-f7gg-47vc
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47691High· 8.7Netty is a network application framework for development of protocol servers and clients
CVE-2026-50011High· 7.5Netty is a network application framework for development of protocol servers and clients
CVE-2026-42584High· 7.3Netty is an asynchronous, event-driven network application framework
CVE-2026-42581Medium· 5.8Netty is an asynchronous, event-driven network application framework
CVE-2026-42579High· 7.5Netty is an asynchronous, event-driven network application framework
CVE-2026-42578High· 7.5Netty is an asynchronous, event-driven network application framework