CVE-2026-44249

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-11 22:16

Updated : 2026-09-11 13:18


NVD link : CVE-2026-44249

Mitre link : CVE-2026-44249

CVE.ORG link : CVE-2026-44249


JSON object : View

Products Affected

netty

  • netty
CWE
CWE-284

Improper Access Control

CWE-697

Incorrect Comparison

CWE-1287

Improper Validation of Specified Type of Input