CVE-2026-44249

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*

History

15 Jun 2026, 02:30

Type Values Removed Values Added
References () https://github.com/netty/netty/releases/tag/netty-4.1.135.Final - () https://github.com/netty/netty/releases/tag/netty-4.1.135.Final - Release Notes
References () https://github.com/netty/netty/releases/tag/netty-4.2.15.Final - () https://github.com/netty/netty/releases/tag/netty-4.2.15.Final - Release Notes
References () https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86 - () https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86 - Vendor Advisory
First Time Netty netty
Netty
CPE cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*

11 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-11 22:16

Updated : 2026-06-15 02:30


NVD link : CVE-2026-44249

Mitre link : CVE-2026-44249

CVE.ORG link : CVE-2026-44249


JSON object : View

Products Affected

netty

  • netty
CWE
CWE-284

Improper Access Control

CWE-697

Incorrect Comparison