Unknown · Netty-Codec-Http3 · CVE-2026-100660
**Name of the Vulnerable Software and Affected Versions**
netty-codec-http3 versions 4.2.0.Final through 4.2.17.Final
**Description**
The HTTP/3 codec retains unbounded per-stream QPACK encoder state. The `QpackEncoder` stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID. These entries are only released when the remote decoder sends a Section Acknowledgment or Stream Cancellation instruction, rather than when the HTTP/3 stream completes. Because there is no limit on the number of tracked streams, field sections, or retained bytes, an unauthenticated HTTP/3 client can trigger unbounded heap growth by advertising a non-zero QPACK dynamic-table capacity and omitting mandatory Section Acknowledgments while issuing sequential requests over a single QUIC connection. This bypasses concurrent-stream limits and can lead to memory exhaustion, resulting in a denial of service.
**Recommendations**
Update netty-codec-http3 to version 4.2.18.Final.