CVE-2026-44249

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*

History

30 Jul 2026, 12:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:48124 -
  • () https://access.redhat.com/errata/RHSA-2026:48151 -

21 Jul 2026, 12:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:41951 -

10 Jul 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:37390 -

09 Jul 2026, 13:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:36820 -

03 Jul 2026, 13:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:34608 -

30 Jun 2026, 03:19

Type Values Removed Values Added
CWE CWE-1287
References
  • () https://access.redhat.com/errata/RHSA-2026:26017 -
  • () https://access.redhat.com/errata/RHSA-2026:26018 -
  • () https://access.redhat.com/errata/RHSA-2026:26586 -
  • () https://access.redhat.com/errata/RHSA-2026:28573 -
  • () https://access.redhat.com/security/cve/CVE-2026-44249 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2488081 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44249.json -

15 Jun 2026, 02:30

Type Values Removed Values Added
First Time Netty netty
Netty
CPE cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
References () https://github.com/netty/netty/releases/tag/netty-4.1.135.Final - () https://github.com/netty/netty/releases/tag/netty-4.1.135.Final - Release Notes
References () https://github.com/netty/netty/releases/tag/netty-4.2.15.Final - () https://github.com/netty/netty/releases/tag/netty-4.2.15.Final - Release Notes
References () https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86 - () https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86 - Vendor Advisory

11 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-11 22:16

Updated : 2026-07-30 12:18


NVD link : CVE-2026-44249

Mitre link : CVE-2026-44249

CVE.ORG link : CVE-2026-44249


JSON object : View

Products Affected

netty

  • netty
CWE
CWE-284

Improper Access Control

CWE-697

Incorrect Comparison

CWE-1287

Improper Validation of Specified Type of Input