Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hussst

#32680of 57,657
8.7Total CVSS
Vulnerabilities · 1
PT-2026-99331
8.7
2026-09-26
Unknown · Netty-Codec-Http3 · CVE-2026-100660
**Name of the Vulnerable Software and Affected Versions** netty-codec-http3 versions 4.2.0.Final through 4.2.17.Final **Description** The HTTP/3 codec retains unbounded per-stream QPACK encoder state. The `QpackEncoder` stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID. These entries are only released when the remote decoder sends a Section Acknowledgment or Stream Cancellation instruction, rather than when the HTTP/3 stream completes. Because there is no limit on the number of tracked streams, field sections, or retained bytes, an unauthenticated HTTP/3 client can trigger unbounded heap growth by advertising a non-zero QPACK dynamic-table capacity and omitting mandatory Section Acknowledgments while issuing sequential requests over a single QUIC connection. This bypasses concurrent-stream limits and can lead to memory exhaustion, resulting in a denial of service. **Recommendations** Update netty-codec-http3 to version 4.2.18.Final.