Skip to main content

Improper Input Validation in io.netty:netty-codec-http3

CVE-2026-100663

  • io.netty:netty-codec-http3
Severity High
Score 8.7/10

Summary

Netty's HTTP/3 codec versions from 4.2.2.Final through 4.2.17.Final does not special-case "HTTP/1 CONNECT" authority-form request-targets when converting HTTP/1 messages to HTTP/3 in "HttpConversionUtil.toHttp3Headers". The authority-form target (e.g., "CONNECT trusted.example:443") is parsed as a URI, so its host is emitted as :scheme, :path is set to "/", and the HTTP/1 Host header is used as :authority; if no Host header is present the "CONNECT" target is dropped. In a Netty-based HTTP/1-to-HTTP/3 proxy or gateway, a remote client can send a "CONNECT" request whose Host header names a different authority than the request-target, producing a malformed "HTTP/3 CONNECT" whose tunnel ":authority" is attacker-controlled. This can bypass tunnel allow-lists, egress policy, backend selection, or audit controls that validate the "HTTP/1 CONNECT" request-target before forwarding over HTTP/3.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-20 - Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Advisory Timeline

  • Published