PT-2026-99331 · Unknown · Netty-Codec-Http3

·

CVE-2026-100660

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions netty-codec-http3 versions 4.2.0.Final through 4.2.17.Final
Description The HTTP/3 codec retains unbounded per-stream QPACK encoder state. The QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID. These entries are only released when the remote decoder sends a Section Acknowledgment or Stream Cancellation instruction, rather than when the HTTP/3 stream completes. Because there is no limit on the number of tracked streams, field sections, or retained bytes, an unauthenticated HTTP/3 client can trigger unbounded heap growth by advertising a non-zero QPACK dynamic-table capacity and omitting mandatory Section Acknowledgments while issuing sequential requests over a single QUIC connection. This bypasses concurrent-stream limits and can lead to memory exhaustion, resulting in a denial of service.
Recommendations Update netty-codec-http3 to version 4.2.18.Final.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100660
GHSA-495P-PCHH-R4MC

Affected Products

Netty-Codec-Http3