PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93562 Red Hat CVE debrief

A flaw in Netty's HTTP/1 decoder allows remote attackers to perform HTTP request smuggling by sending specially crafted HTTP requests with malformed Transfer-Encoding headers. This could potentially bypass security controls or access unauthorized resources. The vulnerability affects Netty-based applications, particularly those using vulnerable versions, and defenders should assess exposure and prioritize patching or mitigation. The CVE record and related advisories provide details on the vulnerability.

Vendor
Red Hat
Product
Red Hat build of Quarkus 3.27.5.SP2
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-10-09
Advisory published
2026-09-18
Advisory updated
2026-10-09

Who should care

Defenders responsible for Netty-based applications, particularly those using vulnerable versions, should assess exposure and prioritize patching or mitigation. This includes verifying the presence of vulnerable Netty versions in the environment, applying patches or mitigations as available, and monitoring for suspicious HTTP requests. Security teams should review security controls for potential bypass vulnerabilities and consider implementing compensating.

Why it matters

CVE-2026-93562 allows remote attackers to perform HTTP request smuggling due to incomplete validation of malformed Transfer-Encoding headers in Netty's HTTP/1 decoder. Defenders should verify the presence of vulnerable Netty versions in their environment and prioritize patching or mitigation efforts.

  • Potential bypass of security controls
  • Unauthorized access to resources
  • Need for verification of vulnerable Netty versions
  • Prioritization of patching or mitigation efforts

Technical summary

The Netty HTTP/1 decoder does not properly validate malformed Transfer-Encoding headers, allowing remote attackers to perform HTTP request smuggling. This vulnerability affects Netty-based applications, particularly those using vulnerable versions. Defenders should assess exposure and prioritize patching or mitigation efforts. The vulnerability can be exploited by sending specially crafted HTTP requests, potentially bypassing security controls or accessing unauthorized resources. The CVE record and related advisories provide details on the vulnerability.

Defensive priority

Defenders should prioritize verifying the presence of vulnerable Netty versions in their environment and applying patches or mitigations as available.

Recommended defensive actions

  • Verify the presence of vulnerable Netty versions in the environment
  • Apply patches or mitigations as available
  • Monitor for suspicious HTTP requests
  • Review security controls for potential bypass vulnerabilities
  • Perform a thorough review of the environment for potential exposure
  • Consider implementing compensating controls for exposed systems
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Red Hat has released advisories RHSA-2026:69440 and RHSA-2026:69470 related to this issue. Defenders should verify the presence of vulnerable Netty versions in their environment and prioritize patching or mitigation efforts. The vulnerability allows remote attackers to perform HTTP request smuggling due to incomplete validation of malformed Transfer-Encoding headers in Netty's HTTP/1 decoder.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93562 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93562

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93562 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93562

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows ht

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93562.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69440

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69470

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-93562

    Supplemental source - vdb-entry, x_refsource_REDHAT

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.