HTTP Request Smuggling Affecting io.netty:netty-codec-http3 package, versions [4.2.2.Final,4.2.18.Final)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.33% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-IONETTY-20154841
  • published27 Sept 2026
  • disclosed26 Sept 2026
  • creditRex Liu

Introduced: 26 Sep 2026

NewCVE-2026-100664  (opens in a new tab)
CWE-436  (opens in a new tab)
CWE-444  (opens in a new tab)

How to fix?

Upgrade io.netty:netty-codec-http3 to version 4.2.18.Final or higher.

Overview

Affected versions of this package are vulnerable to HTTP Request Smuggling in HttpConversionUtil.toHttp3Headers(HttpMessage, boolean), reached through Http3FrameToHttpObjectCodec(false), which processes the Host header before the authority carried in an absolute-form request-target, so a conflicting Host wins over the request-target's own authority, contrary to RFC 9112. An attacker can make the converted request carry an authority different from the one in the request-target, skewing virtual-host routing, allowlist checks, backend selection, cache keys, and URL generation, by sending GET https://trusted.example/admin HTTP/1.1 with Host: attacker.example, which is translated to :authority: attacker.example. This requires Netty to be deployed as an HTTP/1 to HTTP/3 gateway or proxy, and the effect is confined to authority interpretation, with no memory corruption or availability impact.

CVSS Base Scores

version 4.0
version 3.1