Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present, carry the same value. A remote unauthenticated peer can send a single HEADERS frame containing both fields with differing, attacker-controlled values; the request is accepted and delivered to the application with two conflicting authorities, allowing routing, virtual-host, and access-control decisions to be bypassed when different components in the request path consult different fields. This issue is fixed in 4.2.18.Final.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present, carry the same value. A remote unauthenticated peer can send a single HEADERS frame containing both fields with differing, attacker-controlled values; the request is accepted and delivered to the application with two conflicting authorities, allowing routing, virtual-host, and access-control decisions to be bypassed when different components in the request path consult different fields. This issue is fixed in 4.2.18.Final. | |
| Title | Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass | |
| First Time appeared |
Netty
Netty netty |
|
| Weaknesses | CWE-444 | |
| CPEs | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netty
Netty netty |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T13:23:26.859Z
Reserved: 2026-09-26T02:33:59.039Z
Link: CVE-2026-100659
No data.
Status : Received
Published: 2026-09-26T14:16:48.830
Modified: 2026-09-26T14:16:48.830
Link: CVE-2026-100659
No data.
OpenCVE Enrichment
Updated: 2026-09-26T15:45:14Z
Weaknesses