HTTP/3 Codec Vulnerability in Netty Affects Proxy Functionality
CVE-2026-100663

8.7HIGH

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100663?

The Netty HTTP/3 codec fails to correctly process HTTP/1 CONNECT authority-form request-targets when converting messages to HTTP/3. This oversight allows remote clients to exploit malformed HTTP/3 CONNECT requests, potentially circumventing security measures designed to validate request-targets. As a result, an attacker could manipulate the ':' authority, thereby weakening security controls such as tunnel allow-lists and egress policies. The vulnerability affects multiple versions of the netty-codec-http3 library and is resolved in version 4.2.18.Final.

Affected Version(s)

netty 4.2.2.Final < 4.2.18.Final

netty 4.2.18.Final

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rexpository
.