Home / Security / Advisories / NTAP-20260626-0020
NTAP-20260626-0020 — June 2026 Apache Netty 4.1 and 4.2 Vulnerabilities in NetApp Products
Published 2026-06-26 · Updated 2026-07-22 · Status: Interim · Exploitation: Public · Severity: HIGH 8.1 · ONTAP affected: No — other NetApp product
Product family: NetApp Console / BlueXP | other NetApp product | highest CVSS: 8.1
CVEs in this advisory
- CVE-2026-44249 — HIGH · CVSS 8.1 · site index
- CVE-2026-44250 · site index
- CVE-2026-44890 · site index
- CVE-2026-44893 · site index
- CVE-2026-48006 · site index
- CVE-2026-48043 — MEDIUM · CVSS 5.3 · site index
- CVE-2026-48059 · site index
- CVE-2026-50010 — HIGH · CVSS 7.5 · site index
- CVE-2026-50011 · site index
- CVE-2026-50020 · site index
- CVE-2026-50560 · site index
- CVE-2026-45416 · site index
- CVE-2026-45536 — MEDIUM · CVSS 4.0 · site index
- CVE-2026-45673 · site index
- CVE-2026-45674 · site index
- CVE-2026-46340 · site index
- CVE-2026-47244 — MEDIUM · CVSS 5.3 · site index
- CVE-2026-47691 · site index
What the CVE records say
CVE-2026-44249 — Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CVE-2026-48043 — Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CVE-2026-50010 — Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm="HTTPS" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CVE-2026-45536 — Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CVE-2026-47244 — Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Affected products
- NetApp Console Agent OVA
References
- https://github.com/netty/netty/security/advisories/GHSA-3244-j874-rhc2 ↗
- https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86 ↗
- https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm ↗
- https://github.com/netty/netty/security/advisories/GHSA-5pvg-856g-cp85 ↗
- https://github.com/netty/netty/security/advisories/GHSA-5w86-c3rq-vjj7 ↗
- https://github.com/netty/netty/security/advisories/GHSA-5x3r-wrvg-rp6q ↗
- https://github.com/netty/netty/security/advisories/GHSA-5xrh-qmmq-w6ch ↗
- https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2026