Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100660— Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention

Quick assessment

Affected
netty netty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Netty 的 HTTP/3 编解码器(io.netty:netty-codec-http3)在 4.2.0.Final 至 4.2.17.Final 版本中存在一个漏洞,该漏洞会导致每个流的 QPACK 编码器状态无限制地保留。QpackEncoder 为每个引用 QPACK 动态表的编码字段段存储一个队列和一个动态表索引跟踪器,并以对等方控制的 QUIC 流 ID 作为键进行关联。这些条目仅远程解码器发送“部分确认”(Section Acknowledgment)或“流取消”(Stream Cancellati

CVSS 7.5 · High EPSS 0.38% · P29
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100660

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention
Source: CVE Program / CVE List V5
Vulnerability Description
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID, and these entries are released only when the remote decoder sends a Section Acknowledgment or Stream Cancellation instruction — not when the HTTP/3 stream completes. There is no limit on the number of tracked streams, field sections, or retained bytes. A remote, unauthenticated HTTP/3 client can advertise a non-zero QPACK dynamic-table capacity, acknowledge the table insertion so the server reuses a dynamically indexed response header, and then omit all mandatory Section Acknowledgments while issuing sequential requests over a single QUIC connection, bypassing concurrent-stream limits and causing unbounded heap growth until the server exhausts memory (denial of service). Fixed in 4.2.18.Final.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
netty netty 0 ~ 4.2.18.Final -

II. Public POCs for CVE-2026-100660

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100660

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100660 (1)

Other References for CVE-2026-100660 (1)

Same Patch Batch · netty · 2026-09-26 · 12 CVEs total

CVE-2026-100655 7.5 HIGH Netty before 4.1.138.Final Denial of Service via SpdySessionHandler
CVE-2026-100663 7.5 HIGH Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3
CVE-2026-100656 7.5 HIGH Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining
CVE-2026-100661 7.5 HIGH Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation
CVE-2026-100665 7.5 HIGH Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass
CVE-2026-100662 7.5 HIGH Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS
CVE-2026-100664 7.5 HIGH Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion
CVE-2026-100657 7.5 HIGH Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder
CVE-2026-100666 7.3 HIGH Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec
CVE-2026-100659 6.5 MEDIUM Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass
CVE-2026-100658 5.3 MEDIUM Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler

IV. Related Vulnerabilities

V. Comments for CVE-2026-100660

No comments yet


Leave a comment