CVE-2026-44249

high

Description

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

References

https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44249.json

https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86

https://github.com/netty/netty/releases/tag/netty-4.2.15.Final

https://github.com/netty/netty/releases/tag/netty-4.1.135.Final

https://bugzilla.redhat.com/show_bug.cgi?id=2488081

https://access.redhat.com/security/cve/CVE-2026-44249

https://access.redhat.com/errata/RHSA-2026:54435

https://access.redhat.com/errata/RHSA-2026:53806

https://access.redhat.com/errata/RHSA-2026:53644

https://access.redhat.com/errata/RHSA-2026:50085

https://access.redhat.com/errata/RHSA-2026:49701

https://access.redhat.com/errata/RHSA-2026:49700

https://access.redhat.com/errata/RHSA-2026:48151

https://access.redhat.com/errata/RHSA-2026:48124

https://access.redhat.com/errata/RHSA-2026:41951

https://access.redhat.com/errata/RHSA-2026:37390

https://access.redhat.com/errata/RHSA-2026:36820

https://access.redhat.com/errata/RHSA-2026:34608

https://access.redhat.com/errata/RHSA-2026:28573

https://access.redhat.com/errata/RHSA-2026:26586

https://access.redhat.com/errata/RHSA-2026:26018

https://access.redhat.com/errata/RHSA-2026:26017

Details

Source: Mitre, NVD

Published: 2026-06-11

Updated: 2026-09-02

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00039