Skip to main content

Improper Input Validation in io.netty:netty-codec-http3

CVE-2026-100664

  • io.netty:netty-codec-http3
Severity High
Score 8.7/10

Summary

Netty's HTTP/3 codec versions from 4.2.2.Final through 4.2.17.Final builds the HTTP/3 ":authority" pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. In "HttpConversionUtil.toHttp3Headers(HttpMessage, boolean)" reached via "Http3FrameToHttpObjectCodec(false)" a non-empty Host header takes precedence over the request-target authority, contrary to the HTTP/1.1 rule that a server receiving an absolute-form request-target must ignore the Host header. In a Netty-based HTTP/1-to-HTTP/3 gateway, proxy, or protocol bridge, a remote client can send a request such as "GET https://trusted.example/admin HTTP/1.1" with "Host: attacker.example", causing components that validate, authorize, or route on the RFC-defined request-target authority to reach a different decision than the upstream HTTP/3 peer, which receives :authority derived from the conflicting Host header. This authority confusion can affect virtual-host routing, allow-list checks, backend selection, cache keys, and URL generation. The advisory reports integrity impact only (no code execution, memory corruption, or availability impact).

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-20 - Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Advisory Timeline

  • Published