Improper Input Validation
CVE-2026-100663
Summary
Netty's HTTP/3 codec versions from 4.2.2.Final through 4.2.17.Final does not special-case "HTTP/1 CONNECT" authority-form request-targets when converting HTTP/1 messages to HTTP/3 in "HttpConversionUtil.toHttp3Headers". The authority-form target (e.g., "CONNECT trusted.example:443") is parsed as a URI, so its host is emitted as :scheme, :path is set to "/", and the HTTP/1 Host header is used as :authority; if no Host header is present the "CONNECT" target is dropped. In a Netty-based HTTP/1-to-HTTP/3 proxy or gateway, a remote client can send a "CONNECT" request whose Host header names a different authority than the request-target, producing a malformed "HTTP/3 CONNECT" whose tunnel ":authority" is attacker-controlled. This can bypass tunnel allow-lists, egress policy, backend selection, or audit controls that validate the "HTTP/1 CONNECT" request-target before forwarding over HTTP/3.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-20 - Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Advisory Timeline
- Published