CVE-2026-45674 is a DNS cache poisoning vulnerability in Netty's DNS resolver module affecting versions before 4.1.135.Final and 4.2.15.Final. The flaw is in io.netty.resolver.dns.DnsResolveContext, specifically the buildAliasMap logic that processes CNAME records from DNS responses. The vulnerable implementation cached CNAME aliases without validating that the record owner was within the authoritative bailiwick of the original queried domain. As a result, a crafted DNS response could introduce out-of-bailiwick CNAME data into Netty's internal resolver cache. This violates expected DNS resolver trust-boundary checks and can cause subsequent lookups to follow attacker-influenced aliases. The issue is classified as insufficient verification of data authenticity.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DNS cache poisoning vulnerability in Netty's DNS resolver caused by insufficient bailiwick validation for CNAME records, allowing malicious aliases to be cached without proper authority checks.
A vulnerability in Netty's DnsResolveContext where the origin (bailiwick) of CNAME records in DNS responses is not properly validated.
A high-severity DNS cache poisoning vulnerability in Netty's netty-resolver-dns module caused by missing bailiwick validation for CNAME records, allowing crafted DNS responses to poison the resolver cache and redirect outbound connections.
A Netty DNS resolver cache-poisoning vulnerability involving out-of-bailiwick CNAME handling in buildAliasMap.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.