Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

fstec логотип

BDU:2026-08933

3 месяца назад

Уязвимость компонента io.netty.handler.codec.dns.DnsCodecUtil фреймворка для разработки сетевых приложений, серверов и клиентов протоколов Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260624-73-0030

около 1 месяца назад

Уязвимость netty

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2026-42579

3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-42579

3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42579

3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-42579

3 месяца назад

Netty is an asynchronous, event-driven network application framework. ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cm33-6792-r9fm

3 месяца назад

Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2308-1

около 2 месяцев назад

Security update for netty, netty-tcnative

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-08933

Уязвимость компонента io.netty.handler.codec.dns.DnsCodecUtil фреймворка для разработки сетевых приложений, серверов и клиентов протоколов Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
3 месяца назад
redos логотип
ROS-20260624-73-0030

Уязвимость netty

CVSS3: 9.1
1%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-42579

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 7.5
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-42579

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42579

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS3: 7.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-42579

Netty is an asynchronous, event-driven network application framework. ...

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-cm33-6792-r9fm

Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)

CVSS3: 7.5
1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2308-1

Security update for netty, netty-tcnative

около 2 месяцев назад

Уязвимостей на страницу