Skip to main content
EPSS 0.2%top 84%

Io.netty:netty resolver dns: Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (CVE-2026-45674)

0
High
Published: 06/08/2026 (06/08/2026, 23:02:26 UTC)
Source: GCVE Database
Product: io.netty:netty-resolver-dns

Description

### Summary Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. ### Details In `io.netty.resolver.dns.DnsResolveContext#buildAliasMap`, the resolver processes the ANSWER section of a DNS response and blindly caches all CNAME records it finds. According to https://datatracker.ietf.org/doc/html/rfc5452#section-6 ``` Care must be taken to only accept data if it is known that the originator is authoritative for the QNAME or a parent of the QNAME. One very simple way to achieve this is to only accept data if it is part of the domain for which the query was intended. ``` ### Impact DNS Cache Poisoning (Bailiwick Bypass). Any application using Netty's DNS resolver is impacted.

CVSS v3.1

Score 8.7high

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Affected software

Mavenghsa
io.netty:netty-resolver-dns
Affected versions
>=4.2.0.Final <4.2.15.Final
Mavenghsa
io.netty:netty-resolver-dns
Affected versions
<4.1.135.Final

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 18:04:05 UTC

Technical Analysis

The vulnerability (CVE-2026-45674) in io.netty:netty-resolver-dns arises from insufficient bailiwick validation of CNAME records in DNS responses. Specifically, in the DnsResolveContext#buildAliasMap method, the resolver caches all CNAME records found in the ANSWER section without verifying that the originator is authoritative for the queried domain or its parent domains, violating RFC 5452 recommendations. This flaw enables DNS cache poisoning attacks by allowing malicious CNAME records to be accepted and cached improperly. The issue affects Netty versions >=4.2.0.Final <4.2.15.Final and all versions <4.1.135.Final. The vulnerability has a CVSS 3.1 score of 8.7 (high severity) with impact on confidentiality and integrity but no known exploits in the wild. Vendor advisories from Red Hat confirm the availability of patches in updated Netty versions (4.1.135.Final and later).

Potential Impact

Successful exploitation allows an attacker to poison the DNS cache of applications using Netty's DNS resolver by injecting malicious CNAME records. This can lead to redirection of DNS queries to attacker-controlled domains, resulting in potential information disclosure and data manipulation. The CVSS score of 8.7 reflects high impact on confidentiality and integrity. There are no reports of active exploitation in the wild at this time.

Mitigation Recommendations

A patch is available that fixes the bailiwick validation issue by upgrading Netty to version 4.1.135.Final or later. Users should apply the vendor-provided updates promptly. The Red Hat advisories for Red Hat build of Quarkus versions 3.27.4.SP1 and 3.33.2.SP1 include this fix. Before applying updates, ensure all previous relevant errata are applied. No additional mitigations are specified by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-676x-f7gg-47vc
Osv Schema Version
1.4.0
Aliases
["CVE-2026-45674"]
Ecosystems
["Maven"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a520efa68715ace4391e518

Added to database: 07/11/2026, 09:38:02 UTC

Last enriched: 08/12/2026, 18:04:05 UTC

Last updated: 09/13/2026, 22:01:34 UTC

Views: 138

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses