Skip to main content

Improper Input Validation

CVE-2026-42579

Severity Low
Score 0/10

Summary

Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. Affected versions are through 4.1.132.Final, from 4.2.0.Alpha1 through 4.2.12.Final and 5.0.0.Alpha2.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-20 - Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

References

Advisory Timeline

  • Published