LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-47691

netty · netty

Published
CVSS8.7
Severityhigh
WeaknessCWE-345
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Description

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record's name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `

References

← Back to the CVE Tracker

Our coverage of CVE-2026-47691

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-47691.