CVE-2026-100665
- EPSS 0.29%
- Veröffentlicht 26.09.2026 13:23:31
- Zuletzt bearbeitet 02.10.2026 16:16:41
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plai...
CVE-2026-100666
- EPSS 0.24%
- Veröffentlicht 26.09.2026 13:23:31
- Zuletzt bearbeitet 30.09.2026 15:22:15
Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by calling pollMethod() once per response, includi...
CVE-2026-100664
- EPSS 0.33%
- Veröffentlicht 26.09.2026 13:23:30
- Zuletzt bearbeitet 28.09.2026 17:17:44
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. In HttpConv...
CVE-2026-100663
- EPSS 0.3%
- Veröffentlicht 26.09.2026 13:23:29
- Zuletzt bearbeitet 28.09.2026 19:16:45
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-...
CVE-2026-100661
- EPSS 0.34%
- Veröffentlicht 26.09.2026 13:23:28
- Zuletzt bearbeitet 02.10.2026 21:16:53
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of continua...
CVE-2026-100662
- EPSS 0.34%
- Veröffentlicht 26.09.2026 13:23:28
- Zuletzt bearbeitet 30.09.2026 15:22:15
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed on the peer-initiat...
CVE-2026-100660
- EPSS 0.38%
- Veröffentlicht 26.09.2026 13:23:27
- Zuletzt bearbeitet 28.09.2026 17:17:44
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references th...
CVE-2026-100658
- EPSS 0.35%
- Veröffentlicht 26.09.2026 13:23:26
- Zuletzt bearbeitet 28.09.2026 22:17:30
Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-100659
- EPSS 0.24%
- Veröffentlicht 26.09.2026 13:23:26
- Zuletzt bearbeitet 28.09.2026 19:16:45
Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present, carry the same value....
CVE-2026-100657
- EPSS 0.34%
- Veröffentlicht 26.09.2026 13:23:25
- Zuletzt bearbeitet 28.09.2026 22:17:30
Rejected reason: This CVE ID has been rejected as a duplicate.