PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93491 Red Hat CVE debrief

CVE-2026-93491 is a high-severity vulnerability in Netty's HttpServerCodec that can lead to a denial of service via unbounded HTTP/1.1 pipeline queue growth, causing memory exhaustion. Defenders should assess exposure, particularly in systems using affected Netty versions, and prioritize verification, patching, and monitoring. The vulnerability allows remote, unauthenticated attackers to exploit this by pipelining HTTP/1.1 requests on a single connection and withholding reads, causing the methodOverflowQueue to grow without limit.

Vendor
Red Hat
Product
Red Hat Build of Apache Camel 3.33.3.SP2
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-10-09
Advisory published
2026-09-18
Advisory updated
2026-10-09

Who should care

Defenders responsible for systems using Netty's HttpServerCodec, particularly those exposed to untrusted HTTP/1.1 connections, should assess exposure and prioritize patching or mitigation.

Why it matters

CVE-2026-93491 is a high-severity vulnerability in Netty's HttpServerCodec that can lead to denial of service via unbounded HTTP/1.1 pipeline queue growth. Defenders should assess exposure, particularly in systems using affected Netty versions, and prioritize verification, patching, and monitoring.

  • Denial of service due to memory exhaustion.
  • Potential for performance degradation under sustained exploitation attempts.
  • Need for verification of affected systems and application of patches.
  • Possible impact on service availability if not mitigated.

Technical summary

CVE-2026-93491 is a high-severity vulnerability in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this by pipelining HTTP/1.1 requests on a single connection and withholding reads, causing the methodOverflowQueue to grow without limit and leading to unbounded heap memory consumption and a denial of service due to memory exhaustion. The vulnerability affects systems using Netty's HttpServerCodec, particularly those exposed to untrusted HTTP/1.1 connections. Defenders should prioritize verifying affected systems, applying vendor patches, and monitoring for suspicious HTTP/1.1 pipelining activity.

Defensive priority

Defenders should prioritize verifying affected systems, applying vendor patches, and monitoring for suspicious HTTP/1.1 pipelining activity.

Recommended defensive actions

  • Verify if systems using Netty's HttpServerCodec are exposed to untrusted HTTP/1.1 connections.
  • Apply patches or updates provided by vendors like Red Hat.
  • Monitor for suspicious HTTP/1.1 pipelining activity.
  • Review and adjust configurations to limit exposure.
  • Perform asset inventory of systems using affected Netty versions.
  • Track exceptions and retest remediated assets.
  • technicalSummary

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Red Hat has released advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257 addressing the issue. Evidence is limited to public CVE and NVD information. Defenders should verify affected systems, review configurations, and apply patches or updates provided by vendors like Red Hat. Additional verification tasks are needed due to limited source detail.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93491 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93491

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93491 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93491

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 pipel

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93491.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69440

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69470

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:70257

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-93491

    Supplemental source - vdb-entry, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://github.com/netty/netty/releases/tag/netty-4.1.138.Final

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/netty/netty/releases/tag/netty-4.2.18.Final

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.