CVE-2026-42579CWE-1286CWE-20CWE-400CWE-626denial-of-service

CVE-2026-42579

High · published May 13, 2026

CVSS v3.1
7.5
EPSS
1%
Percentile
60.7
In the wild
Unconfirmed
What it is

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.01006 · 60.7th percentile
Weaknesses
CWE-1286 · Improper Validation of Syntactic Correctness of Input; CWE-20 · Improper Input Validation; CWE-400 · Uncontrolled Resource Consumption; CWE-626 · Null Byte Interaction Error (Poison Null Byte)
Published
2026-05-13T23:17Z
Affected products (2)
ProductVersionsFixed in
netty/netty< 4.1.1334.1.133
netty/netty≥ 4.2.0, < 4.2.134.2.13
References (14)
EPSS history
Timeline
  • 13 MAY 18:01Z
    Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
    cvelistv5