PT-2026-99332 · Unknown · Netty-Codec-Http3

·

CVE-2026-100661

·

Published

2026-09-26

·

Updated

2026-10-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions netty-codec-http3 versions 4.2.0.Final through 4.2.17.Final
Description A denial-of-service issue exists in the QPACK prefixed-integer decoder QpackUtil.decodePrefixedInteger() that fails to bound the number of continuation bytes processed. A remote, unauthenticated peer can open a QPACK unidirectional stream and send a first byte with all prefix bits set, followed by a continuous sequence of 0x80 continuation bytes. This causes the ByteToMessageDecoder cumulator to grow without bound and forces each decode() call to re-scan the entire accumulated buffer, resulting in O(N^2) CPU cost. This leads to event-loop CPU starvation and unbounded per-connection heap growth, potentially causing an OutOfMemoryError across all configurations.
Recommendations Update to version 4.2.18.Final.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100661
GHSA-V5P2-HMGX-3XRX

Affected Products

Netty-Codec-Http3