HTTP/3 Codec Vulnerability in Netty Affects Proxy Functionality
CVE-2026-100663
8.7HIGH
What is CVE-2026-100663?
The Netty HTTP/3 codec fails to correctly process HTTP/1 CONNECT authority-form request-targets when converting messages to HTTP/3. This oversight allows remote clients to exploit malformed HTTP/3 CONNECT requests, potentially circumventing security measures designed to validate request-targets. As a result, an attacker could manipulate the ':' authority, thereby weakening security controls such as tunnel allow-lists and egress policies. The vulnerability affects multiple versions of the netty-codec-http3 library and is resolved in version 4.2.18.Final.
Affected Version(s)
netty 4.2.2.Final < 4.2.18.Final
netty 4.2.18.Final
