PT-2026-99330 · Unknown · Netty-Codec-Http3

·

CVE-2026-100659

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions netty-codec-http3 versions 4.2.0.Final through 4.2.17.Final
Description The HTTP/3 codec fails to enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field must carry the same value when both are present. A remote unauthenticated peer can send a single HEADERS frame containing both fields with differing, attacker-controlled values. The request is accepted and delivered to the application with two conflicting authorities, which can allow the bypass of routing, virtual-host, and access-control decisions if different components in the request path consult different fields.
Recommendations Update netty-codec-http3 to version 4.2.18.Final.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100659
GHSA-Q9PG-8H3J-8HVM

Affected Products

Netty-Codec-Http3