CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100663

HIGHCVSS 7.5NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-form target (e.g., "CONNECT trusted.example:443")

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100663 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100663

HIGHCVSS 7.5NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-form target (e.g., "CONNECT trusted.example:443")

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]