Skip to content

[GHSA-676x-f7gg-47vc] Add fix commit reference - #10187

Open
stanleys12 wants to merge 1 commit into
github:stanleys12/advisory-improvement-10187from
stanleys12:stanleys12-GHSA-676x-f7gg-47vc
Open

stanleys12 wants to merge 1 commit into
github:stanleys12/advisory-improvement-10187from
stanleys12:stanleys12-GHSA-676x-f7gg-47vc

Conversation

@stanleys12

Copy link
Copy Markdown

I'm adding the fix commit for GHSA-676x-f7gg-47vc / CVE-2026-45674, the missing bailiwick check on CNAME records in DnsResolveContext. The commit is eeed84177eb584ff10bbfa7e0fe0ae233ee68a9d, the security-fork merge "DNS: Only cache CNAME if part of the queried domain". Its message says it closes the "DNS Cache Poisoning (Bailiwick Bypass)", and it only touches DnsResolveContext and its tests. It's in netty-4.2.15.Final, which is the patched version. The 4.1 backport is PR #16873 (merge commit 5749d7822f0bf18e2eb0ea1f10d7b7181456ad75, included in netty-4.1.135.Final).

@github-actions
github-actions Bot changed the base branch from main to stanleys12/advisory-improvement-10187 October 6, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant