8.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeNetty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses.
In io.netty.resolver.dns.DnsResolveContext#buildAliasMap, the resolver processes the ANSWER section of a DNS response and blindly caches all CNAME records it finds.
According to https://datatracker.ietf.org/doc/html/rfc5452#section-6
DNS Cache Poisoning (Bailiwick Bypass). Any application using Netty's DNS resolver is impacted.