PatchSiren cyber security CVE debrief
CVE-2026-93491 Red Hat CVE debrief
CVE-2026-93491 is a high-severity vulnerability in Netty's HttpServerCodec that can lead to a denial of service via unbounded HTTP/1.1 pipeline queue growth, causing memory exhaustion. Defenders should assess exposure, particularly in systems using affected Netty versions, and prioritize verification, patching, and monitoring. The vulnerability allows remote, unauthenticated attackers to exploit this by pipelining HTTP/1.1 requests on a single connection and withholding reads, causing the methodOverflowQueue to grow without limit.
- Vendor
- Red Hat
- Product
- Red Hat Build of Apache Camel 3.33.3.SP2
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for systems using Netty's HttpServerCodec, particularly those exposed to untrusted HTTP/1.1 connections, should assess exposure and prioritize patching or mitigation.
Why it matters
CVE-2026-93491 is a high-severity vulnerability in Netty's HttpServerCodec that can lead to denial of service via unbounded HTTP/1.1 pipeline queue growth. Defenders should assess exposure, particularly in systems using affected Netty versions, and prioritize verification, patching, and monitoring.
- Denial of service due to memory exhaustion.
- Potential for performance degradation under sustained exploitation attempts.
- Need for verification of affected systems and application of patches.
- Possible impact on service availability if not mitigated.
Technical summary
CVE-2026-93491 is a high-severity vulnerability in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this by pipelining HTTP/1.1 requests on a single connection and withholding reads, causing the methodOverflowQueue to grow without limit and leading to unbounded heap memory consumption and a denial of service due to memory exhaustion. The vulnerability affects systems using Netty's HttpServerCodec, particularly those exposed to untrusted HTTP/1.1 connections. Defenders should prioritize verifying affected systems, applying vendor patches, and monitoring for suspicious HTTP/1.1 pipelining activity.
Defensive priority
Defenders should prioritize verifying affected systems, applying vendor patches, and monitoring for suspicious HTTP/1.1 pipelining activity.
Recommended defensive actions
- Verify if systems using Netty's HttpServerCodec are exposed to untrusted HTTP/1.1 connections.
- Apply patches or updates provided by vendors like Red Hat.
- Monitor for suspicious HTTP/1.1 pipelining activity.
- Review and adjust configurations to limit exposure.
- Perform asset inventory of systems using affected Netty versions.
- Track exceptions and retest remediated assets.
- technicalSummary
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Red Hat has released advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257 addressing the issue. Evidence is limited to public CVE and NVD information. Defenders should verify affected systems, review configurations, and apply patches or updates provided by vendors like Red Hat. Additional verification tasks are needed due to limited source detail.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93491 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93491
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93491 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93491
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 pipel
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93491.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69440
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69470
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:70257
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93491
Supplemental source - vdb-entry, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://github.com/netty/netty/releases/tag/netty-4.1.138.Final
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/netty/netty/releases/tag/netty-4.2.18.Final
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.