PT-2026-99334 · Unknown · Netty-Codec-Http3
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
netty-codec-http3 versions 4.2.2.Final through 4.2.17.Final
Description
The HTTP/3 codec fails to properly handle HTTP/1 CONNECT authority-form request-targets during the conversion of HTTP/1 messages to HTTP/3 within the
toHttp3Headers function of HttpConversionUtil. The authority-form target is parsed as a URI, causing the host to be emitted as :scheme, the :path to be set to /, and the HTTP/1 Host header to be used as :authority. If the Host header is missing, the CONNECT target is discarded. In scenarios involving a Netty-based HTTP/1-to-HTTP/3 proxy or gateway, a remote client can provide a Host header that differs from the request-target. This results in a malformed HTTP/3 CONNECT request where the tunnel :authority is controlled by the attacker, potentially bypassing tunnel allow-lists, egress policies, backend selection, or audit controls that validate the request-target before forwarding.Recommendations
Update netty-codec-http3 to version 4.2.18.Final.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty-Codec-Http3