PatchSiren cyber security CVE debrief
CVE-2026-93558 Red Hat CVE debrief
A vulnerability in Netty's WebSocketServerExtensionHandler can lead to unbounded per-connection queue growth, causing a Denial of Service (DoS) due to excessive memory consumption. This issue can be exploited by a remote, unauthenticated attacker using HTTP/1.1 pipelining to send requests faster than the application can respond. The vulnerability affects various products, including Red Hat Build of Apache Camel 3.33.3.SP2 and Red Hat build of Quarkus 3.27.5.SP2. Defenders should assess exposure and apply patches or mitigations to prevent potential DoS attacks.
- Vendor
- Red Hat
- Product
- Red Hat Build of Apache Camel 3.33.3.SP2
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for Red Hat Build of Apache Camel 3.33.3.SP2, Red Hat build of Quarkus 3.27.5.SP2, and other affected systems should assess exposure and apply patches or mitigations to prevent potential DoS attacks.
Why it matters
CVE-2026-93558 vulnerability in Netty's WebSocketServerExtensionHandler can lead to DoS attacks; defenders should assess exposure and apply patches.
- Potential Denial of Service (DoS) due to excessive memory consumption
- Need to assess exposure of affected systems
- Priority to apply patches or mitigations
- Verification of system updates and security patches
Technical summary
The vulnerability in Netty's WebSocketServerExtensionHandler allows for unbounded per-connection queue growth, leading to a Denial of Service (DoS) due to excessive memory consumption. This can be exploited by a remote, unauthenticated attacker using HTTP/1.1 pipelining. The issue arises from the handler's inability to limit the growth of the queue, which can be triggered by sending requests faster than the application can respond. Affected systems include Red Hat Build of Apache Camel 3.33.3.SP2 and Red Hat build of Quarkus 3.27.5.SP2. Defenders should prioritize assessing exposure and applying patches or mitigations.
Defensive priority
Defenders should prioritize assessing exposure and applying patches or mitigations to prevent potential DoS attacks. This involves reviewing affected systems, such as Red Hat Build of Apache Camel 3.33.3.SP2, Red Hat build of Quarkus 3.27.5.SP2, and others, and ensuring they are updated with the latest security patches.
Recommended defensive actions
- Assess exposure of affected systems, such as Red Hat Build of Apache Camel 3.33.3.SP2 and Red Hat build of Quarkus 3.27.5.SP2
- Apply patches or mitigations provided by vendors, such as Red Hat
- Monitor systems for potential DoS attacks
- Review and update incident response plans
- Perform vulnerability scanning to identify exposed systems
- Implement compensating controls for exposed systems
- Track and verify system updates and security patches
Evidence notes
The CVE Program record and NVD vulnerability detail provide information on the vulnerability. Red Hat has released advisories, such as RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257, addressing this issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93558 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93558
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93558 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93558
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextens
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93558.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69440
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69470
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:70257
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93558
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.