← Späť na vyhľadávanie CVE

CVE-2026-47691

Netty

Popis

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty-s `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record-s name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `authoritativeDnsServerCache` under the parent domain-s key. This bypasses standard bailiwick rules, where a server authoritative for a subdomain should not be trusted to provide authoritative records for its parent. The poisoned cache is then used for all future resolutions under the parent domain-s key. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

CVSS 8.7EPSS 0.318%Riziko 0.89
Zobraziť zdroj
Zverejnené
2026-06-12 16:16:30
Dotknuté verzie
cannotmatch
Typ
Knižnica
Posledná úprava
2026-08-04 13:18:50
Vektor
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N