Io.netty:netty resolver dns: Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (CVE-2026-45674)
### Summary Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. ### Details In `io.netty.resolver.dns.DnsResolveContext#buildAliasMap`, the resolver processes the ANSWER section of a DNS response and blindly caches all CNAME records it finds. According to https://datatracker.ietf.org/doc/html/rfc5452#section-6 ``` Care must be taken to only accept data if it is known that the originator is authoritative for the QNAME or a parent of the QNAME. One very simple way to achieve this is to only accept data if it is part of the domain for which the query was intended. ``` ### Impact DNS Cache Poisoning (Bailiwick Bypass). Any application using Netty's DNS resolver is impacted.
AI Analysis
Technical Summary
The vulnerability in io.netty.resolver.dns.DnsResolveContext stems from insufficient bailiwick validation of CNAME records in DNS responses. Specifically, in the method buildAliasMap, the resolver caches all CNAME records found in the ANSWER section without verifying that the originator is authoritative for the queried domain name or a parent domain, as recommended by RFC 5452 section 6. This flaw enables DNS cache poisoning attacks via bailiwick bypass, impacting any application using Netty's DNS resolver.
Potential Impact
Successful exploitation allows an attacker to poison the DNS cache of applications using Netty's DNS resolver by injecting malicious CNAME records that are not properly validated for origin authority. This can lead to clients resolving domain names to attacker-controlled IP addresses, resulting in potential confidentiality and integrity breaches. The CVSS vector indicates network attack complexity is high, no privileges or user interaction required, and the impact is high on confidentiality and integrity but not availability.
Mitigation Recommendations
Red Hat has released security updates for their build of Quarkus that include fixes for this vulnerability by upgrading Netty to version 4.1.135.Final. Applying these updates (e.g., Quarkus 3.33.2.SP1 or 3.27.4.SP1) will remediate the issue. Users should ensure all relevant errata are applied before updating. No other specific mitigations are indicated in the vendor advisories. Patch status is confirmed via Red Hat advisories; users should apply the official fixes.
Io.netty:netty resolver dns: Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (CVE-2026-45674)
Description
### Summary Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. ### Details In `io.netty.resolver.dns.DnsResolveContext#buildAliasMap`, the resolver processes the ANSWER section of a DNS response and blindly caches all CNAME records it finds. According to https://datatracker.ietf.org/doc/html/rfc5452#section-6 ``` Care must be taken to only accept data if it is known that the originator is authoritative for the QNAME or a parent of the QNAME. One very simple way to achieve this is to only accept data if it is part of the domain for which the query was intended. ``` ### Impact DNS Cache Poisoning (Bailiwick Bypass). Any application using Netty's DNS resolver is impacted.
CVSS v3.1
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in io.netty.resolver.dns.DnsResolveContext stems from insufficient bailiwick validation of CNAME records in DNS responses. Specifically, in the method buildAliasMap, the resolver caches all CNAME records found in the ANSWER section without verifying that the originator is authoritative for the queried domain name or a parent domain, as recommended by RFC 5452 section 6. This flaw enables DNS cache poisoning attacks via bailiwick bypass, impacting any application using Netty's DNS resolver.
Potential Impact
Successful exploitation allows an attacker to poison the DNS cache of applications using Netty's DNS resolver by injecting malicious CNAME records that are not properly validated for origin authority. This can lead to clients resolving domain names to attacker-controlled IP addresses, resulting in potential confidentiality and integrity breaches. The CVSS vector indicates network attack complexity is high, no privileges or user interaction required, and the impact is high on confidentiality and integrity but not availability.
Mitigation Recommendations
Red Hat has released security updates for their build of Quarkus that include fixes for this vulnerability by upgrading Netty to version 4.1.135.Final. Applying these updates (e.g., Quarkus 3.33.2.SP1 or 3.27.4.SP1) will remediate the issue. Users should ensure all relevant errata are applied before updating. No other specific mitigations are indicated in the vendor advisories. Patch status is confirmed via Red Hat advisories; users should apply the official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-676x-f7gg-47vc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-45674"]
- Ecosystems
- ["Maven"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a520efa68715ace4391e518
Added to database: 07/11/2026, 09:38:02 UTC
Last enriched: 07/11/2026, 10:14:56 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.