🔐 CVE Alert

CVE-2026-59900

UNKNOWN 0.0

Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.

CWE CWE-444
Vendor netty
Product netty
Published Jul 29, 2026
Last Updated Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for netty netty

Be the first to know when new unknown vulnerabilities affecting netty netty are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

netty / netty
>= 4.2.0.Final, < 4.2.16.Final < 4.1.136.Final

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj github.com: https://github.com/netty/netty/releases/tag/netty-4.1.136.Final github.com: https://github.com/netty/netty/releases/tag/netty-4.2.16.Final