PT-2026-99331 · Unknown · Netty-Codec-Http3
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
netty-codec-http3 versions 4.2.0.Final through 4.2.17.Final
Description
The HTTP/3 codec retains unbounded per-stream QPACK encoder state. The
QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID. These entries are only released when the remote decoder sends a Section Acknowledgment or Stream Cancellation instruction, rather than when the HTTP/3 stream completes. Because there is no limit on the number of tracked streams, field sections, or retained bytes, an unauthenticated HTTP/3 client can trigger unbounded heap growth by advertising a non-zero QPACK dynamic-table capacity and omitting mandatory Section Acknowledgments while issuing sequential requests over a single QUIC connection. This bypasses concurrent-stream limits and can lead to memory exhaustion, resulting in a denial of service.Recommendations
Update netty-codec-http3 to version 4.2.18.Final.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty-Codec-Http3