Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44249

Опубликовано: 11 июн. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
Версия до 4.1.135 (исключая)
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 4.2.15 (исключая)

EPSS

Процентиль: 60%
0.01025
Низкий

8.1 High

CVSS3

Дефекты

CWE-284
CWE-1287

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

CVSS3: 8.1
redhat
около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

CVSS3: 8.1
debian
около 2 месяцев назад

Netty is a network application framework for development of protocol s ...

CVSS3: 8.1
github
2 месяца назад

Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking

suse-cvrf
около 1 месяца назад

Security update for netty, netty-tcnative

EPSS

Процентиль: 60%
0.01025
Низкий

8.1 High

CVSS3

Дефекты

CWE-284
CWE-1287