以下是该漏洞描述信息的中文翻译: Netty 的 HTTP/3 编解码器(io.netty:netty-codec-http3)在 4.2.2.Final 至 4.2.17.Final 版本中,在考虑绝对形式 HTTP/1 请求目标的授权(authority)之前,会从 HTTP/1 的 Host 头部构建 HTTP/3 的 :authority 伪头部。在 HttpConversionUtil.toHttp3Headers(HttpMessage, boolean) 方法中(通过 Http3FrameToHttp
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100655 | 7.5 HIGH | Netty before 4.1.138.Final Denial of Service via SpdySessionHandler |
| CVE-2026-100663 | 7.5 HIGH | Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3 |
| CVE-2026-100656 | 7.5 HIGH | Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining |
| CVE-2026-100661 | 7.5 HIGH | Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation |
| CVE-2026-100660 | 7.5 HIGH | Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention |
| CVE-2026-100665 | 7.5 HIGH | Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass |
| CVE-2026-100662 | 7.5 HIGH | Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS |
| CVE-2026-100657 | 7.5 HIGH | Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder |
| CVE-2026-100666 | 7.3 HIGH | Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec |
| CVE-2026-100659 | 6.5 MEDIUM | Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass |
| CVE-2026-100658 | 5.3 MEDIUM | Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler |
No comments yet