PT-2026-99335 · Unknown · Netty-Codec-Http3

·

CVE-2026-100664

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions netty-codec-http3 versions 4.2.2.Final through 4.2.17.Final
Description The HTTP/3 codec incorrectly builds the :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. This occurs in the toHttp3Headers(HttpMessage, boolean) function, reached via Http3FrameToHttpObjectCodec(false), where a non-empty Host header takes precedence over the request-target authority. This behavior contradicts HTTP/1.1 rules requiring servers to ignore the Host header when an absolute-form request-target is present. In scenarios involving a Netty-based HTTP/1-to-HTTP/3 gateway, proxy, or protocol bridge, a remote client can trigger authority confusion by sending conflicting headers. This can lead to discrepancies in virtual-host routing, allow-list checks, backend selection, cache keys, and URL generation between the gateway and the upstream HTTP/3 peer.
Recommendations Update to version 4.2.18.Final.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100664
GHSA-HFR2-X62W-V49H

Affected Products

Netty-Codec-Http3