{"ghsa_id":"GHSA-3qp7-7mw8-wx86","cve_id":"CVE-2026-44249","url":"https://api.github.com/advisories/GHSA-3qp7-7mw8-wx86","html_url":"https://github.com/advisories/GHSA-3qp7-7mw8-wx86","summary":"Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking","description":"### Summary\nAn attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions.\n\n### Details\n`io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress)` method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask.\n\n### Impact\nAccess Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.","type":"reviewed","severity":"high","repository_advisory_url":"https://api.github.com/repos/netty/netty/security-advisories/GHSA-3qp7-7mw8-wx86","source_code_location":"https://github.com/netty/netty","identifiers":[{"value":"GHSA-3qp7-7mw8-wx86","type":"GHSA"},{"value":"CVE-2026-44249","type":"CVE"}],"references":["https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-44249","https://github.com/advisories/GHSA-3qp7-7mw8-wx86"],"published_at":"2026-06-08T19:00:33Z","updated_at":"2026-06-12T19:27:08Z","github_reviewed_at":"2026-06-08T19:00:33Z","nvd_published_at":"2026-06-11T22:16:56Z","withdrawn_at":null,"vulnerabilities":[{"package":{"ecosystem":"maven","name":"io.netty:netty-handler"},"vulnerable_version_range":">= 4.2.0.Final, <= 4.2.14.Final","first_patched_version":"4.2.15.Final","vulnerable_functions":[]},{"package":{"ecosystem":"maven","name":"io.netty:netty-handler"},"vulnerable_version_range":"<= 4.1.134.Final","first_patched_version":"4.1.135.Final","vulnerable_functions":[]}],"cvss_severities":{"cvss_v3":{"vector_string":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","score":8.1},"cvss_v4":{"vector_string":null,"score":0.0}},"cwes":[{"cwe_id":"CWE-284","name":"Improper Access Control"},{"cwe_id":"CWE-697","name":"Incorrect Comparison"}],"credits":[{"user":{"login":"violetagg","id":696661,"node_id":"MDQ6VXNlcjY5NjY2MQ==","avatar_url":"https://avatars.githubusercontent.com/u/696661?v=4","gravatar_id":"","url":"https://api.github.com/users/violetagg","html_url":"https://github.com/violetagg","followers_url":"https://api.github.com/users/violetagg/followers","following_url":"https://api.github.com/users/violetagg/following{/other_user}","gists_url":"https://api.github.com/users/violetagg/gists{/gist_id}","starred_url":"https://api.github.com/users/violetagg/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/violetagg/subscriptions","organizations_url":"https://api.github.com/users/violetagg/orgs","repos_url":"https://api.github.com/users/violetagg/repos","events_url":"https://api.github.com/users/violetagg/events{/privacy}","received_events_url":"https://api.github.com/users/violetagg/received_events","type":"User","user_view_type":"public","site_admin":false},"type":"reporter"}],"cvss":{"vector_string":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","score":8.1},"epss":{"percentage":0.01025,"percentile":0.60946}}