CVE detail
CVE-2026-45674
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:41951access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 12, 2026, 3:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45674.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJun 12, 2026, 3:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2488400bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 12, 2026, 3:16 PM - https://access.redhat.com/security/cve/CVE-2026-45674access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 12, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:37390access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 12, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:34608access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 12, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:26586access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 12, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:26018access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 12, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:26017access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 12, 2026, 3:16 PM No excerpt available.
Exploitgithub.comJun 12, 2026, 3:16 PMNo excerpt available.
Exploitgithub.comJun 12, 2026, 3:16 PMNo excerpt available.
Exploitgithub.comJun 12, 2026, 3:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-47691CVSS 8.7 · High
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficien…
- CVE-2025-12245CVSS 5.5 · Medium
A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the…
- CVE-2025-5320CVSS 6.3 · Medium
A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is_valid_origin of the component CORS Handler. The manipulati…
- CVE-2025-2346CVSS 6.3 · Medium
A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown code of the component Domain H…
- CVE-2023-27360CVSS 8.8 · High
NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installatio…
- CVE-2024-24557CVSS 6.9 · Medium
Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scrat…