Authority Confusion in Netty's HTTP/3 Codec
CVE-2026-100664
8.7HIGH
What is CVE-2026-100664?
The Netty HTTP/3 codec versions 4.2.2.Final through 4.2.17.Final encounter an authority confusion vulnerability. This issue arises when the codec builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header without properly considering the request-target's authority, leading to potentially conflicting interpretations of this authority in a Netty-based HTTP/1-to-HTTP/3 gateway. As a result, a remote client may manipulate headers to influence validation, authorization, and routing decisions made by components, potentially compromising security controls that depend on RFC-defined request-target authorities. Users are advised to upgrade to version 4.2.18.Final to mitigate this risk.
Affected Version(s)
netty 4.2.2.Final < 4.2.18.Final
netty 4.2.18.Final
