CVE-2026-44894
netty netty, Red Hat build of Apache Camel - HawtIO 4
Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns false (server will not send Retry — acceptable), but validateToken() unconditionally `return 0`. In QuicheQuicServerCodec.handlePacket(), a non-negative return from validateToken() is interpreted as 'token is valid, ODCID starts at offset 0', causing the server to call quiche_accept as if the client's address had been validated by a Retry round-trip. Per RFC 9000 §8...
- CVSS
- 7.5
- EPSS
- 0.14% 4.04% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.13