GHSA-676x-f7gg-47vc
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
Quick fix
GHSA-676x-f7gg-47vc — io.netty:netty-resolver-dns: upgrade to the fixed version with the command below.
# pom.xml: bump <version>4.2.15.Final</version> for io.netty:netty-resolver-dnsDetails
### Summary Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses.
### Details In `io.netty.resolver.dns.DnsResolveContext#buildAliasMap`, the resolver processes the ANSWER section of a DNS response and blindly caches all CNAME records it finds.
According to https://datatracker.ietf.org/doc/html/rfc5452#section-6
``` Care must be taken to only accept data if it is known that the originator is authoritative for the QNAME or a parent of the QNAME. One very simple way to achieve this is to only accept data if it is part of the domain for which the query was intended. ```
### Impact DNS Cache Poisoning (Bailiwick Bypass). Any application using Netty's DNS resolver is impacted.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.2.0.FinalFixed in: 4.2.15.Final# pom.xml: bump <version>4.2.15.Final</version> for io.netty:netty-resolver-dns0Fixed in: 4.1.135.Final# pom.xml: bump <version>4.1.135.Final</version> for io.netty:netty-resolver-dnsReferences
- https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-45674[ADVISORY]
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45674.json[WEB]
- https://github.com/netty/netty/releases/tag/netty-4.2.15.Final[WEB]
- https://github.com/netty/netty/releases/tag/netty-4.1.135.Final[WEB]
- https://github.com/netty/netty[PACKAGE]
- https://bugzilla.redhat.com/show_bug.cgi?id=2488400[WEB]
- https://access.redhat.com/security/cve/CVE-2026-45674[WEB]
- https://access.redhat.com/errata/RHSA-2026:62260[WEB]
- https://access.redhat.com/errata/RHSA-2026:54435[WEB]
- https://access.redhat.com/errata/RHSA-2026:53806[WEB]
- https://access.redhat.com/errata/RHSA-2026:53644[WEB]
- https://access.redhat.com/errata/RHSA-2026:50085[WEB]
- https://access.redhat.com/errata/RHSA-2026:49701[WEB]
- https://access.redhat.com/errata/RHSA-2026:49700[WEB]
- https://access.redhat.com/errata/RHSA-2026:48151[WEB]
- https://access.redhat.com/errata/RHSA-2026:41951[WEB]
- https://access.redhat.com/errata/RHSA-2026:37390[WEB]
- https://access.redhat.com/errata/RHSA-2026:34608[WEB]
- https://access.redhat.com/errata/RHSA-2026:26586[WEB]
- https://access.redhat.com/errata/RHSA-2026:26018[WEB]
- https://access.redhat.com/errata/RHSA-2026:26017[WEB]