Skip to content

UID2-7278: upgrade Netty to 4.1.135.Final (CVE-2026-44249/45416/45674/47691)#412

Merged
cYKatherine merged 1 commit into
mainfrom
kchen-UID2-7278-netty-4.1.135
Jun 11, 2026
Merged

UID2-7278: upgrade Netty to 4.1.135.Final (CVE-2026-44249/45416/45674/47691)#412
cYKatherine merged 1 commit into
mainfrom
kchen-UID2-7278-netty-4.1.135

Conversation

@cYKatherine

Copy link
Copy Markdown
Contributor

Summary

  • Netty upgrade (UID2-7278): bump netty.version from 4.1.133.Final4.1.135.Final in pom.xml. Fixes 4 HIGH CVEs: CVE-2026-44249 (netty-handler IPv6 filter bypass), CVE-2026-45416 (netty-handler SNI DoS), CVE-2026-45674 (netty-resolver-dns DNS cache poisoning), CVE-2026-47691 (netty-resolver-dns NS bailiwick bypass).
  • CVE-2026-42577 expiry extended: 2026-06-082026-09-11 (3 months; no 4.1.x fix available per UID2-7035).

Jira

Test plan

  • CI vulnerability scan passes (Trivy no longer flags CVE-2026-44249/45416/45674/47691)
  • Unit tests pass

- pom.xml: netty.version 4.1.133.Final → 4.1.135.Final (fixes CVE-2026-44249,
  CVE-2026-45416 in netty-handler; CVE-2026-45674, CVE-2026-47691 in netty-resolver-dns)
- .trivyignore: extend CVE-2026-42577 expiry to 2026-09-11 (no 4.1.x fix yet)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@cYKatherine cYKatherine merged commit 590aa35 into main Jun 11, 2026
4 checks passed
@cYKatherine cYKatherine deleted the kchen-UID2-7278-netty-4.1.135 branch June 11, 2026 06:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants