PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93558 Red Hat CVE debrief

A vulnerability in Netty's WebSocketServerExtensionHandler can lead to unbounded per-connection queue growth, causing a Denial of Service (DoS) due to excessive memory consumption. This issue can be exploited by a remote, unauthenticated attacker using HTTP/1.1 pipelining to send requests faster than the application can respond. The vulnerability affects various products, including Red Hat Build of Apache Camel 3.33.3.SP2 and Red Hat build of Quarkus 3.27.5.SP2. Defenders should assess exposure and apply patches or mitigations to prevent potential DoS attacks.

Vendor
Red Hat
Product
Red Hat Build of Apache Camel 3.33.3.SP2
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-10-09
Advisory published
2026-09-18
Advisory updated
2026-10-09

Who should care

Defenders responsible for Red Hat Build of Apache Camel 3.33.3.SP2, Red Hat build of Quarkus 3.27.5.SP2, and other affected systems should assess exposure and apply patches or mitigations to prevent potential DoS attacks.

Why it matters

CVE-2026-93558 vulnerability in Netty's WebSocketServerExtensionHandler can lead to DoS attacks; defenders should assess exposure and apply patches.

  • Potential Denial of Service (DoS) due to excessive memory consumption
  • Need to assess exposure of affected systems
  • Priority to apply patches or mitigations
  • Verification of system updates and security patches

Technical summary

The vulnerability in Netty's WebSocketServerExtensionHandler allows for unbounded per-connection queue growth, leading to a Denial of Service (DoS) due to excessive memory consumption. This can be exploited by a remote, unauthenticated attacker using HTTP/1.1 pipelining. The issue arises from the handler's inability to limit the growth of the queue, which can be triggered by sending requests faster than the application can respond. Affected systems include Red Hat Build of Apache Camel 3.33.3.SP2 and Red Hat build of Quarkus 3.27.5.SP2. Defenders should prioritize assessing exposure and applying patches or mitigations.

Defensive priority

Defenders should prioritize assessing exposure and applying patches or mitigations to prevent potential DoS attacks. This involves reviewing affected systems, such as Red Hat Build of Apache Camel 3.33.3.SP2, Red Hat build of Quarkus 3.27.5.SP2, and others, and ensuring they are updated with the latest security patches.

Recommended defensive actions

  • Assess exposure of affected systems, such as Red Hat Build of Apache Camel 3.33.3.SP2 and Red Hat build of Quarkus 3.27.5.SP2
  • Apply patches or mitigations provided by vendors, such as Red Hat
  • Monitor systems for potential DoS attacks
  • Review and update incident response plans
  • Perform vulnerability scanning to identify exposed systems
  • Implement compensating controls for exposed systems
  • Track and verify system updates and security patches

Evidence notes

The CVE Program record and NVD vulnerability detail provide information on the vulnerability. Red Hat has released advisories, such as RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257, addressing this issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93558 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93558

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93558 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93558

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextens

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93558.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69440

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69470

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:70257

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-93558

    Supplemental source - vdb-entry, x_refsource_REDHAT

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.