{"id":"CVE-2026-59900","aliases":["GHSA-c69g-56f8-xwqj"],"title":"Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass","summary":"Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass","severity":"medium","cwe":["CWE-444"],"vendor":"netty","product":"io.netty:netty-codec-http2","ecosystem":"maven","affected":["io.netty:netty-codec-http2 >= 4.2.0.Final, <= 4.2.15.Final","io.netty:netty-codec-http2 < 4.1.136.Final"],"patched":["io.netty:netty-codec-http2 4.2.16.Final","io.netty:netty-codec-http2 4.1.136.Final"],"published":"2026-07-22","updated":"2026-07-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-c69g-56f8-xwqj","references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"},{"url":"https://github.com/advisories/GHSA-c69g-56f8-xwqj"}],"tags":["ghsa","maven"],"ingestedAt":"2026-07-22T22:06:57.658Z","epss":0.00232,"epssPercentile":0.14397,"slug":"CVE-2026-59900","body":"## Overview\n\nNetty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values.\n\n## Affected packages\n\n- `io.netty:netty-codec-http2 >= 4.2.0.Final, <= 4.2.15.Final`\n- `io.netty:netty-codec-http2 < 4.1.136.Final`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `io.netty:netty-codec-http2 4.2.16.Final`\n- `io.netty:netty-codec-http2 4.1.136.Final`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}