CVE detail
CVE-2026-42579
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42579.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 13, 2026, 7:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2477217bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 13, 2026, 7:17 PM - https://access.redhat.com/security/cve/CVE-2026-42579access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 7:17 PM - https://access.redhat.com/errata/RHSA-2026:37390access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 7:17 PM - https://access.redhat.com/errata/RHSA-2026:36820access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 7:17 PM - https://access.redhat.com/errata/RHSA-2026:28010access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 7:17 PM - https://access.redhat.com/errata/RHSA-2026:25123access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 7:17 PM - https://access.redhat.com/errata/RHSA-2026:24502access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 7:17 PM - https://access.redhat.com/errata/RHSA-2026:23808access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 7:17 PM No excerpt available.
Exploitgithub.comMay 13, 2026, 7:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-61160CVSS 8.1 · High
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is…
- CVE-2026-60719CVSS 9.9 · Critical
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0…
- CVE-2026-60620CVSS 6.4 · Medium
Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supported version that is affected is 9.2. Dif…
- CVE-2026-50196CVSS 7.5 · High
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eureka prior to versions 4.2.0 a…
- CVE-2026-46910CVSS 9.1 · Critical
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0…
- CVE-2026-46679CVSS 7.5 · High
libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer t…