Back

MEDIUM

Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port

Published Jun 12, 2026

Description

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack). Versions 4.1.135.Final and 4.2.15.Final patch the issue.

Affected products

Remediation

Red Hat statement

Moderate: This flaw in Netty's DNS resolver could allow a remote attacker to perform DNS cache poisoning. The vulnerability stems from the use of a predictable pseudo-random number generator for DNS transaction IDs and a static UDP source port, which reduces the entropy of DNS queries. This makes it easier for an attacker to redirect network traffic to malicious servers, potentially leading to traffic interception or Man-in-the-Middle attacks for applications using the default Netty DNS resolver in Red Hat products.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 12, 2026
Updated Jun 12, 2026
Reserved May 12, 2026
CISA Vulnrichment
Updated Jun 12, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 12, 2026
ENISA EUVD
Assigner GitHub_M
Published Jun 12, 2026
Updated Jun 12, 2026
Exploited since n/a
EUVD-2026-36445 GHSA-XMV7-R254-6Q78