PT-2026-99334 · Unknown · Netty-Codec-Http3

·

CVE-2026-100663

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions netty-codec-http3 versions 4.2.2.Final through 4.2.17.Final
Description The HTTP/3 codec fails to properly handle HTTP/1 CONNECT authority-form request-targets during the conversion of HTTP/1 messages to HTTP/3 within the toHttp3Headers function of HttpConversionUtil. The authority-form target is parsed as a URI, causing the host to be emitted as :scheme, the :path to be set to /, and the HTTP/1 Host header to be used as :authority. If the Host header is missing, the CONNECT target is discarded. In scenarios involving a Netty-based HTTP/1-to-HTTP/3 proxy or gateway, a remote client can provide a Host header that differs from the request-target. This results in a malformed HTTP/3 CONNECT request where the tunnel :authority is controlled by the attacker, potentially bypassing tunnel allow-lists, egress policies, backend selection, or audit controls that validate the request-target before forwarding.
Recommendations Update netty-codec-http3 to version 4.2.18.Final.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100663
GHSA-JGPH-CGQ3-C627

Affected Products

Netty-Codec-Http3