PT-2026-99335 · Unknown · Netty-Codec-Http3
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
netty-codec-http3 versions 4.2.2.Final through 4.2.17.Final
Description
The HTTP/3 codec incorrectly builds the
:authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. This occurs in the toHttp3Headers(HttpMessage, boolean) function, reached via Http3FrameToHttpObjectCodec(false), where a non-empty Host header takes precedence over the request-target authority. This behavior contradicts HTTP/1.1 rules requiring servers to ignore the Host header when an absolute-form request-target is present. In scenarios involving a Netty-based HTTP/1-to-HTTP/3 gateway, proxy, or protocol bridge, a remote client can trigger authority confusion by sending conflicting headers. This can lead to discrepancies in virtual-host routing, allow-list checks, backend selection, cache keys, and URL generation between the gateway and the upstream HTTP/3 peer.Recommendations
Update to version 4.2.18.Final.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty-Codec-Http3