{"id":"CVE-2026-59900","aliases":["GHSA-c69g-56f8-xwqj"],"url":"https://o3.security/vulnerability/CVE-2026-59900","summary":"Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass","details":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","published":"2026-07-29T17:58:35.543Z","modified":"2026-08-12T03:51:13.779419365Z","cvss":null,"epss":{"score":0.00232,"percentile":0.14035,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.netty:netty-codec-http2","fixedVersion":"4.2.16.Final"},{"ecosystem":"Maven","name":"io.netty:netty-codec-http2","fixedVersion":"4.1.136.Final"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"},{"type":"WEB","url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59900.json"},{"type":"ADVISORY","url":"https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59900"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.779419365Z"}}