Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade io.netty:netty-codec-http3 to version 4.2.18.Final or higher.
Affected versions of this package are vulnerable to HTTP Request Smuggling in HttpConversionUtil.toHttp3Headers(HttpMessage, boolean), reached through Http3FrameToHttpObjectCodec(false), which processes the Host header before the authority carried in an absolute-form request-target, so a conflicting Host wins over the request-target's own authority, contrary to RFC 9112. An attacker can make the converted request carry an authority different from the one in the request-target, skewing virtual-host routing, allowlist checks, backend selection, cache keys, and URL generation, by sending GET https://trusted.example/admin HTTP/1.1 with Host: attacker.example, which is translated to :authority: attacker.example. This requires Netty to be deployed as an HTTP/1 to HTTP/3 gateway or proxy, and the effect is confined to authority interpretation, with no memory corruption or availability impact.