Executive brief
Netty is a widely used networking framework that helps developers build high-performance servers and clients. A flaw in its IP filtering component allows attackers to bypass security rules designed to restrict access based on IPv6 addresses. This could allow unauthorized users to connect to sensitive services or bypass network-level protections, potentially leading to unauthorized data access or service disruption.
Technical details
An access control bypass vulnerability exists in the netty-handler component of the Netty framework. The root cause is an incorrect bitwise masking operation within the IpSubnetFilterRule.compareTo() method, where the incoming IP address is incorrectly compared against the networkAddress instead of the subnetMask. This logic error allows valid public IPv6 addresses to bypass configured subnet restrictions. The attack is network-reachable and requires no privileges or user interaction, though it is rated with high complexity as it depends on specific IPv6 address configurations. The issue is resolved in versions 4.1.135.Final and 4.2.15.Final.
Affected products
- Netty Project Netty < 4.1.135.Final, >= 4.2.0.Final, <= 4.2.14.Final
Timeline
- 2026-06-02: patched: Versions 4.1.135.Final and 4.2.15.Final released
- 2026-06-05: advisory: GitHub Security Advisory GHSA-3qp7-7mw8-wx86 published
- 2026-06-11: disclosed: CVE-2026-44249 published to NVD