CVE Explorer
CVE-2026-56746
Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluat
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"netty","vendor":"netty","versions":[{"status":"affected","version":">= 4.2.0.Final, < 4.2.16.Final"},{"status":"affected","version":">= 4.1.0.Final, < 4.1.136.Final"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:daa83002de6d582b4fc0fe342587d09045bf9de69fa0af3afe8b0ea6ce144386 · sha256:e176b487b907eee5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:daa83002de6d582b4fc0fe342587d09045bf9de69fa0af3afe8b0ea6ce144386 · sha256:e176b487b907eee5… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:daa83002de6d582b4fc0fe342587d09045bf9de69fa0af3afe8b0ea6ce144386 · sha256:e176b487b907eee5… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","tags":["x_refsource_MISC"],"url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:daa83002de6d582b4fc0fe342587d09045bf9de69fa0af3afe8b0ea6ce144386 · sha256:e176b487b907eee5… · /containers/cna/references/1
{"name":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","tags":["x_refsource_MISC"],"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:daa83002de6d582b4fc0fe342587d09045bf9de69fa0af3afe8b0ea6ce144386 · sha256:e176b487b907eee5… · /containers/cna/references/2
{"name":"https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5","tags":["x_refsource_CONFIRM"],"url":"https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:daa83002de6d582b4fc0fe342587d09045bf9de69fa0af3afe8b0ea6ce144386 · sha256:e176b487b907eee5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.