8.2
CVE-2026-93569
- EPSS 0.37%
- Veröffentlicht 18.09.2026 14:27:54
- Zuletzt bearbeitet 22.09.2026 19:16:58
- Erkennungen
Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authority, overriding the request-target authority
A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat AMQ Broker 7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Apache Camel 4 for Quarkus 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Apache Camel for Spring Boot 4
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Apicurio Registry 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Debezium 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Build of Keycloak
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Data Grid 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Fuse 7
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat JBoss Enterprise Application Platform 7
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat JBoss Enterprise Application Platform 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Single Sign-On 7
Default Statusaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.311 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
|
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
https://access.redhat.com/security/cve/CVE-2026-93569
https://bugzilla.redhat.com/show_bug.cgi?id=2536962
https://access.redhat.com/errata/RHSA-2026:69470
https://access.redhat.com/errata/RHSA-2026:69440
https://access.redhat.com/errata/RHSA-2026:70257