Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100666— Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec

Quick assessment

Affected
netty netty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Netty 的 HttpServerCodec(io.netty:netty-codec-http)在 4.2.0.Final 到 4.2.16.Final 版本之间,以及 4.1.136.Final 及更早版本中存在安全漏洞。这些版本中的 HttpServerCodec 为每个出站响应通过调用 pollMethod() 来与一个入站请求进行配对,包括 1xx 信息性响应。 如果客户端使用 HTTP/1.1 管道(pipelining)发送一个携带了 “Expect: 100-continue” 报头的 GET 请

CVSS 7.3 · High EPSS 0.24% · P14
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100666

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec
Source: CVE Program / CVE List V5
Vulnerability Description
Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by calling pollMethod() once per response, including for 1xx informational responses. If a client pipelines an HTTP/1.1 GET carrying an Expect: 100-continue header followed by a HEAD request, the 100 Continue response consumes the queued GET method, so the subsequent 200 OK for the GET is paired with HEAD and its body is dropped, while the following 200 OK for the HEAD request is written with a body. This desynchronizes HTTP parsing on the connection: the GET entity is never delivered and the HEAD response body is interpreted as the GET body, resulting in response splitting and unsafe connection reuse. Fixed in 4.2.17.Final and 4.1.137.Final.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
netty netty 4.2.0.Final ~ 4.2.17.Final -
netty netty 0 ~ 4.1.137.Final -

II. Public POCs for CVE-2026-100666

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100666

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100666 (1)

Other References for CVE-2026-100666 (1)

Same Patch Batch · netty · 2026-09-26 · 12 CVEs total

CVE-2026-100655 7.5 HIGH Netty before 4.1.138.Final Denial of Service via SpdySessionHandler
CVE-2026-100663 7.5 HIGH Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3
CVE-2026-100656 7.5 HIGH Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining
CVE-2026-100661 7.5 HIGH Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation
CVE-2026-100660 7.5 HIGH Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention
CVE-2026-100665 7.5 HIGH Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass
CVE-2026-100662 7.5 HIGH Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS
CVE-2026-100664 7.5 HIGH Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion
CVE-2026-100657 7.5 HIGH Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder
CVE-2026-100659 6.5 MEDIUM Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass
CVE-2026-100658 5.3 MEDIUM Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler

IV. Related Vulnerabilities

V. Comments for CVE-2026-100666

No comments yet


Leave a comment