Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qp7-7mw8-wx86

Опубликовано: 08 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking

Summary

An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions.

Details

io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress) method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask.

Impact

Access Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.

Пакеты

Наименование

io.netty:netty-handler

maven
Затронутые версииВерсия исправления

>= 4.2.0.Final, <= 4.2.14.Final

4.2.15.Final

Наименование

io.netty:netty-handler

maven
Затронутые версииВерсия исправления

<= 4.1.134.Final

4.1.135.Final

EPSS

Процентиль: 60%
0.01025
Низкий

8.1 High

CVSS3

Дефекты

CWE-284
CWE-697

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

CVSS3: 8.1
redhat
около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

CVSS3: 8.1
nvd
около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

CVSS3: 8.1
debian
около 2 месяцев назад

Netty is a network application framework for development of protocol s ...

suse-cvrf
около 1 месяца назад

Security update for netty, netty-tcnative

EPSS

Процентиль: 60%
0.01025
Низкий

8.1 High

CVSS3

Дефекты

CWE-284
CWE-697