THREAT OPS › Threat News › [NVD] CVE-2026-44249 (HIGH 8.1) — Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid pub
[NVD] CVE-2026-44249 (HIGH 8.1) — Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid pub
CVE-2026-44249 CVSS: 8.1 HIGH Published: 2026-06-11T22:16:56.707
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions
MITRE ATT&CK techniques
- IP AddressesT1590.005
Indicators of compromise
- CVE-2026-44249cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-44249