### Summary An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. ### Details `io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress)` method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask. ### Impact Access Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.
Update io.netty:netty-handler to 4.2.15.Final; io.netty:netty-handler to 4.1.135.Final if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanNetty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking affects io.netty:netty-handler (maven), io.netty:netty-handler (maven). Severity is high. ### Summary An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. ### Details `io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress)` method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask. ### Impact Access Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| io.netty:netty-handlermaven |
### Summary An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. ### Details `io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress)` method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask. ### Impact Access Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.
Update io.netty:netty-handler to 4.2.15.Final; io.netty:netty-handler to 4.1.135.Final if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanNetty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking affects io.netty:netty-handler (maven), io.netty:netty-handler (maven). Severity is high. ### Summary An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. ### Details `io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress)` method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask. ### Impact Access Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| io.netty:netty-handlermaven |
| >=4.2.0.Final,<=4.2.14.Final |
| 4.2.15.Final |
| io.netty:netty-handlermaven | <=4.1.134.Final | 4.1.135.Final |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=4.2.0.Final,<=4.2.14.Final |
| 4.2.15.Final |
| io.netty:netty-handlermaven | <=4.1.134.Final | 4.1.135.Final |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard