CVE-2026-45674: Netty

Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

Affected products

  • Netty Netty: before 4.1.135 (fixed in 4.1.135); from 4.2.0, before 4.2.15 (fixed in 4.2.15)

Published 2026-06-12. Last modified 2026-09-18.