Summary
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
Advisory details
Netty's HTTP/2-to-HTTP/1.x translation layer (Http2StreamFrameToHttpObjectCodec and InboundHttp2ToHttpAdapter) fails to deduplicate or validate Host headers when an HTTP/2 client supplies both the :authority pseudo-header and a literal host header in a single HEADERS frame. The translator maps :authority to Host and separately copies the literal host header, producing an HttpRequest object containing two Host headers with attacker-controlled differing values.
References
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-55087
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
- MEDIUMCVE-2026-62899
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
- MEDIUMCVE-2026-71554
h2: Duplicate Host header could facilitate request smuggling
- HIGHCVE-2026-71324
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
- MEDIUMCVE-2026-69243
AIOHTTP: HTTP request smuggling via WebSocket upgrade
- MEDIUMCVE-2026-16728
undici vulnerable to downstream response desynchronization via retry interceptor