Executive brief
Netty is a popular Java networking library used by many applications to handle HTTP/2 and HTTP/3 connections. A vulnerability allows remote attackers to send specially crafted Extended CONNECT requests that Netty incorrectly processes, causing loss of critical protocol information. This can allow attackers to bypass security policies like authorization and routing logic, potentially gaining unauthorized access or circumventing intended restrictions.
Technical details
A flaw in Netty's HTTP-object conversion path causes HTTP/2 and HTTP/3 Extended CONNECT requests to be incorrectly processed as regular HTTP/1.1 CONNECT requests. This misinterpretation results in loss of critical protocol and path information during request conversion. The vulnerability is reachable remotely over the network without requiring authentication. An attacker can exploit this by crafting specialized Extended CONNECT requests to bypass routing, authorization, and other security policies that depend on accurate protocol and path metadata. Applications using Netty for HTTP/2 or HTTP/3 communication are affected.
Affected products
- Netty Project Netty <UNKNOWN>
Timeline
- 2026-09-18: disclosed