CVE-2026-100659: Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass

Published Sep 26, 2026
·
Updated

Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present, carry the same value. A remote unauthenticated peer can send a single HEADERS frame containing both fields with differing, attacker-controlled values; the request is accepted and delivered to the application with two conflicting authorities, allowing routing, virtual-host, and access-control decisions to be bypassed when different components in the request path consult different fields. This issue is fixed in 4.2.18.Final.

Affected Software

1 affected component
maven/io.netty/netty-codec-http3>=4.2.0.Final<=4.2.17.Final

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade io.netty:netty-codec-http3 to a version that resolves this vulnerability.

    Fixed in 4.2.18.Final

Event History

Sep 26, 2026
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are at practical risk?

Deployments using Netty's HTTP/3 codec are at risk when different components along the request path make routing, virtual-host, or access-control decisions using different authority values. The bypass depends on those components interpreting the :authority pseudo-header and host header differently.

2

Does exploitation require authentication or user interaction?

No. A remote unauthenticated peer can exploit the issue by sending a single HTTP/3 HEADERS frame containing both fields with differing attacker-controlled values.

3

What version resolves the issue?

The issue is fixed in netty-codec-http3 version 4.2.18.Final. The affected range described is 4.2.0.Final through 4.2.17.Final.

4

How can teams look for attempted exploitation?

Inspect HTTP/3 requests for cases where both the :authority pseudo-header and literal host header are present but have different values. Such requests are the condition described as being accepted and passed to the application by affected versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203