Threat intelligence dashboard
CVE-2026-100659medium

Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass

Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present, carry the same value. A remote unauthenticated peer can send a single HEADERS frame containing both fields with differing, attacker-controlled values; the request is accepted and delivered to the application with two conflicting authorities, allowing routing, virtual-host, and access-control decisions to be bypassed when different components in the request path consult different fields. This issue is fixed in 4.2.18.Final.

Risk score

6.9

CVSS 4.0

Vendor
netty
Product
netty
CWE
CWE-444
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

netty

netty

Version / rangeStatusType
4.2.0.Final to before 4.2.18.Finalaffectedcustom
4.2.18.Finalunaffectedcustom

Technical metrics

6.9

CVSS 4.0

Severity
medium
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

6.5

CVSS 3.1

Severity
medium
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N