---
id: CVE-2026-59900
aliases:
  - GHSA-c69g-56f8-xwqj
title: >-
  Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x
  Translation Leads to Request Routing Bypass
summary: >-
  Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x
  Translation Leads to Request Routing Bypass
severity: medium
cwe:
  - CWE-444
vendor: netty
product: 'io.netty:netty-codec-http2'
ecosystem: maven
affected:
  - 'io.netty:netty-codec-http2 >= 4.2.0.Final, <= 4.2.15.Final'
  - 'io.netty:netty-codec-http2 < 4.1.136.Final'
patched:
  - 'io.netty:netty-codec-http2 4.2.16.Final'
  - 'io.netty:netty-codec-http2 4.1.136.Final'
published: '2026-07-22'
updated: '2026-07-22'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-c69g-56f8-xwqj'
references:
  - url: 'https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj'
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.1.136.Final'
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.2.16.Final'
  - url: 'https://github.com/advisories/GHSA-c69g-56f8-xwqj'
tags:
  - ghsa
  - maven
ingestedAt: '2026-07-22T22:06:57.658Z'
epss: 0.00398
epssPercentile: 0.31297
---

## Overview

Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values.

## Affected packages

- `io.netty:netty-codec-http2 >= 4.2.0.Final, <= 4.2.15.Final`
- `io.netty:netty-codec-http2 < 4.1.136.Final`

## Remediation

Upgrade to a patched release:

- `io.netty:netty-codec-http2 4.2.16.Final`
- `io.netty:netty-codec-http2 4.1.136.Final`
