OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100663

HIGH · CVSS 7.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Netty's HTTP/3 codec versions 4.2.2.Final through 4.2.17.Final are vulnerable to a flaw in handling HTTP/1 CONNECT requests, allowing attackers to manipulate the tunnel :authority in malformed HTTP/3 CONNECT messages. This vulnerability can lead to bypassing security controls such as tunnel allow-lists and egress policies, potentially exposing sensitive backend services to unauthorized access. Organizations using Netty for HTTP/1-to-HTTP/3 proxy or gateway functionalities should prioritize upgrading to version 4.2.18.Final to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100663
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-form target (e.g., "CONNECT trusted.example:443") is parsed as a URI, so its host is emitted as :scheme, :path is set to "/", and the HTTP/1 Host header is used as :authority; if no Host header is present the CONNECT target is dropped. In a Netty-based HTTP/1-to-HTTP/3 proxy or gateway, a remote client can send a CONNECT request whose Host header names a different authority than the request-target, producing a malformed HTTP/3 CONNECT whose tunnel :authority is attacker-controlled. This can bypass tunnel allow-lists, egress policy, backend selection, or audit controls that validate the HTTP/1 CONNECT request-target before forwarding over HTTP/3. The issue is fixed in 4.2.18.Final.