← All Advisories

CVE-2026-93569

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93569

Key Details

CVECVE-2026-93569
CVSS Score / Version8.2 (High) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is high; availability impact is none.
Affected productssee table below
Classified asCWE-444 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat JBoss Enterprise Application Platform 7
Red HatRed Hat Single Sign-On 7
Red HatRed Hat build of Apache Camel for Spring Boot 4
Red HatRed Hat Data Grid 8
Red HatRed Hat build of Apache Camel 4 for Quarkus 3
Red HatRed Hat build of Apicurio Registry 3
Red HatRed Hat build of Debezium 3
Red HatRed Hat JBoss Enterprise Application Platform 8
Red HatRed Hat Build of Keycloak
Red HatRed Hat Fuse 7
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93569
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93569