Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 27 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass | Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass |
Sun, 27 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present, carry the same value. A remote unauthenticated peer can send a single HEADERS frame containing both fields with differing, attacker-controlled values; the request is accepted and delivered to the application with two conflicting authorities, allowing routing, virtual-host, and access-control decisions to be bypassed when different components in the request path consult different fields. This issue is fixed in 4.2.18.Final. | |
| Title | Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass | |
| First Time appeared |
Netty
Netty netty |
|
| Weaknesses | CWE-444 | |
| CPEs | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netty
Netty netty |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T18:17:29.170Z
Reserved: 2026-09-26T02:33:59.039Z
Link: CVE-2026-100659
Updated: 2026-09-28T18:17:03.491Z
Status : Deferred
Published: 2026-09-26T14:16:48.830
Modified: 2026-09-28T19:16:45.480
Link: CVE-2026-100659
OpenCVE Enrichment
Updated: 2026-09-26T15:45:14Z