#1150165 netty: CVE-2026-100666

Package:
src:netty
Source:
src:netty
Submitter:
Salvatore Bonaccorso
Date:
2026-10-06 11:35:03 UTC
Severity:
normal
Tags:
#1150165#5
Date:
2026-10-06 11:33:45 UTC
From:
To:
Hi,

The following vulnerability was published for netty.

CVE-2026-100666[0]:
| Netty's HttpServerCodec (io.netty:netty-codec-http) in versions
| 4.2.0.Final through 4.2.16.Final and in versions up to and including
| 4.1.136.Final pairs each outbound response with an inbound request
| by calling pollMethod() once per response, including for 1xx
| informational responses. If a client pipelines an HTTP/1.1 GET
| carrying an Expect: 100-continue header followed by a HEAD request,
| the 100 Continue response consumes the queued GET method, so the
| subsequent 200 OK for the GET is paired with HEAD and its body is
| dropped, while the following 200 OK for the HEAD request is written
| with a body. This desynchronizes HTTP parsing on the connection: the
| GET entity is never delivered and the HEAD response body is
| interpreted as the GET body, resulting in response splitting and
| unsafe connection reuse. Fixed in 4.2.17.Final and 4.1.137.Final.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-100666
https://www.cve.org/CVERecord?id=CVE-2026-100666
[1] https://github.com/netty/netty/security/advisories/GHSA-2g6j-r8q9-5hr8

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore