PatchSiren cyber security CVE debrief
CVE-2026-93562 Red Hat CVE debrief
A flaw in Netty's HTTP/1 decoder allows remote attackers to perform HTTP request smuggling by sending specially crafted HTTP requests with malformed Transfer-Encoding headers. This could potentially bypass security controls or access unauthorized resources. The vulnerability affects Netty-based applications, particularly those using vulnerable versions, and defenders should assess exposure and prioritize patching or mitigation. The CVE record and related advisories provide details on the vulnerability.
- Vendor
- Red Hat
- Product
- Red Hat build of Quarkus 3.27.5.SP2
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for Netty-based applications, particularly those using vulnerable versions, should assess exposure and prioritize patching or mitigation. This includes verifying the presence of vulnerable Netty versions in the environment, applying patches or mitigations as available, and monitoring for suspicious HTTP requests. Security teams should review security controls for potential bypass vulnerabilities and consider implementing compensating.
Why it matters
CVE-2026-93562 allows remote attackers to perform HTTP request smuggling due to incomplete validation of malformed Transfer-Encoding headers in Netty's HTTP/1 decoder. Defenders should verify the presence of vulnerable Netty versions in their environment and prioritize patching or mitigation efforts.
- Potential bypass of security controls
- Unauthorized access to resources
- Need for verification of vulnerable Netty versions
- Prioritization of patching or mitigation efforts
Technical summary
The Netty HTTP/1 decoder does not properly validate malformed Transfer-Encoding headers, allowing remote attackers to perform HTTP request smuggling. This vulnerability affects Netty-based applications, particularly those using vulnerable versions. Defenders should assess exposure and prioritize patching or mitigation efforts. The vulnerability can be exploited by sending specially crafted HTTP requests, potentially bypassing security controls or accessing unauthorized resources. The CVE record and related advisories provide details on the vulnerability.
Defensive priority
Defenders should prioritize verifying the presence of vulnerable Netty versions in their environment and applying patches or mitigations as available.
Recommended defensive actions
- Verify the presence of vulnerable Netty versions in the environment
- Apply patches or mitigations as available
- Monitor for suspicious HTTP requests
- Review security controls for potential bypass vulnerabilities
- Perform a thorough review of the environment for potential exposure
- Consider implementing compensating controls for exposed systems
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Red Hat has released advisories RHSA-2026:69440 and RHSA-2026:69470 related to this issue. Defenders should verify the presence of vulnerable Netty versions in their environment and prioritize patching or mitigation efforts. The vulnerability allows remote attackers to perform HTTP request smuggling due to incomplete validation of malformed Transfer-Encoding headers in Netty's HTTP/1 decoder.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93562 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93562
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93562 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93562
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows ht
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93562.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69440
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69470
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93562
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.