Io.netty:netty resolver dns: Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (CVE-2026-45674)
### Summary Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. ### Details In `io.netty.resolver.dns.DnsResolveContext#buildAliasMap`, the resolver processes the ANSWER section of a DNS response and blindly caches all CNAME records it finds. According to https://datatracker.ietf.org/doc/html/rfc5452#section-6 ``` Care must be taken to only accept data if it is known that the originator is authoritative for the QNAME or a parent of the QNAME. One very simple way to achieve this is to only accept data if it is part of the domain for which the query was intended. ``` ### Impact DNS Cache Poisoning (Bailiwick Bypass). Any application using Netty's DNS resolver is impacted.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-45674) in io.netty:netty-resolver-dns arises from insufficient bailiwick validation of CNAME records in DNS responses. Specifically, in the DnsResolveContext#buildAliasMap method, the resolver caches all CNAME records found in the ANSWER section without verifying that the originator is authoritative for the queried domain or its parent domains, violating RFC 5452 recommendations. This flaw enables DNS cache poisoning attacks by allowing malicious CNAME records to be accepted and cached improperly. The issue affects Netty versions >=4.2.0.Final <4.2.15.Final and all versions <4.1.135.Final. The vulnerability has a CVSS 3.1 score of 8.7 (high severity) with impact on confidentiality and integrity but no known exploits in the wild. Vendor advisories from Red Hat confirm the availability of patches in updated Netty versions (4.1.135.Final and later).
Potential Impact
Successful exploitation allows an attacker to poison the DNS cache of applications using Netty's DNS resolver by injecting malicious CNAME records. This can lead to redirection of DNS queries to attacker-controlled domains, resulting in potential information disclosure and data manipulation. The CVSS score of 8.7 reflects high impact on confidentiality and integrity. There are no reports of active exploitation in the wild at this time.
Mitigation Recommendations
A patch is available that fixes the bailiwick validation issue by upgrading Netty to version 4.1.135.Final or later. Users should apply the vendor-provided updates promptly. The Red Hat advisories for Red Hat build of Quarkus versions 3.27.4.SP1 and 3.33.2.SP1 include this fix. Before applying updates, ensure all previous relevant errata are applied. No additional mitigations are specified by the vendor.
Io.netty:netty resolver dns: Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (CVE-2026-45674)
Description
### Summary Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. ### Details In `io.netty.resolver.dns.DnsResolveContext#buildAliasMap`, the resolver processes the ANSWER section of a DNS response and blindly caches all CNAME records it finds. According to https://datatracker.ietf.org/doc/html/rfc5452#section-6 ``` Care must be taken to only accept data if it is known that the originator is authoritative for the QNAME or a parent of the QNAME. One very simple way to achieve this is to only accept data if it is part of the domain for which the query was intended. ``` ### Impact DNS Cache Poisoning (Bailiwick Bypass). Any application using Netty's DNS resolver is impacted.
CVSS v3.1
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-45674) in io.netty:netty-resolver-dns arises from insufficient bailiwick validation of CNAME records in DNS responses. Specifically, in the DnsResolveContext#buildAliasMap method, the resolver caches all CNAME records found in the ANSWER section without verifying that the originator is authoritative for the queried domain or its parent domains, violating RFC 5452 recommendations. This flaw enables DNS cache poisoning attacks by allowing malicious CNAME records to be accepted and cached improperly. The issue affects Netty versions >=4.2.0.Final <4.2.15.Final and all versions <4.1.135.Final. The vulnerability has a CVSS 3.1 score of 8.7 (high severity) with impact on confidentiality and integrity but no known exploits in the wild. Vendor advisories from Red Hat confirm the availability of patches in updated Netty versions (4.1.135.Final and later).
Potential Impact
Successful exploitation allows an attacker to poison the DNS cache of applications using Netty's DNS resolver by injecting malicious CNAME records. This can lead to redirection of DNS queries to attacker-controlled domains, resulting in potential information disclosure and data manipulation. The CVSS score of 8.7 reflects high impact on confidentiality and integrity. There are no reports of active exploitation in the wild at this time.
Mitigation Recommendations
A patch is available that fixes the bailiwick validation issue by upgrading Netty to version 4.1.135.Final or later. Users should apply the vendor-provided updates promptly. The Red Hat advisories for Red Hat build of Quarkus versions 3.27.4.SP1 and 3.33.2.SP1 include this fix. Before applying updates, ensure all previous relevant errata are applied. No additional mitigations are specified by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-676x-f7gg-47vc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-45674"]
- Ecosystems
- ["Maven"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a520efa68715ace4391e518
Added to database: 07/11/2026, 09:38:02 UTC
Last enriched: 08/12/2026, 18:04:05 UTC
Last updated: 09/13/2026, 22:01:34 UTC
Views: 138
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.