PatchSiren cyber security CVE debrief
CVE-2026-93564 Red Hat CVE debrief
A reference-count leak in the HAProxy PROXY-v2 message decoder in Netty allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers, potentially leading to memory exhaustion and a Denial of Service (DoS) for the affected system. This issue affects multiple Red Hat products that utilize Netty. The vulnerability has a high CVSS score of 7.5 and is considered HIGH severity. The CVE Program and NVD provide official records of this vulnerability. Red Hat has released advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257 related to this issue.
- Vendor
- Red Hat
- Product
- Red Hat Build of Apache Camel 3.33.3.SP2
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for Red Hat products that utilize Netty, especially those with internet-exposed services, should assess their exposure and prioritize updating vulnerable versions of netty-codec-haproxy.
Why it matters
CVE-2026-93564 is a high-severity vulnerability in Netty's HAProxy PROXY-v2 message decoder that can lead to a Denial of Service (DoS). Defenders should prioritize verifying exposure in Red Hat products, especially those with internet-exposed services, and update vulnerable versions of netty-codec-haproxy as soon as available.
- Memory exhaustion leading to Denial of Service (DoS)
- Potential for remote, unauthenticated exploitation
- Affected systems require immediate version updates for netty-codec-haproxy
- Verification of exposure and remediation are critical for systems with internet-exposed services
Technical summary
The vulnerability exists in the netty-codec-haproxy package, which is used by multiple Red Hat products. A remote, unauthenticated attacker can exploit this by sending specially crafted PROXY-protocol v2 headers, potentially leading to memory exhaustion and a Denial of Service (DoS). The issue arises from a reference-count leak in the HAProxy PROXY-v2 message decoder. Defenders should prioritize verifying exposure in Red Hat products that use Netty, especially those with internet-exposed services. They should assess if their systems are using vulnerable versions of netty-codec-haproxy and update to patched versions as soon as available.
Defensive priority
Defenders should prioritize verifying exposure in Red Hat products that use Netty, especially those with internet-exposed services. They should assess if their systems are using vulnerable versions of netty-codec-haproxy and update to patched versions as soon as available.
Recommended defensive actions
- Verify if your Red Hat products are using vulnerable versions of netty-codec-haproxy.
- Update to patched versions of netty-codec-haproxy as soon as available.
- Monitor systems for unusual memory usage or DoS symptoms.
- Review and apply Red Hat advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257.
- Perform a thorough review of system configurations and internet-exposed services.
- Consider implementing compensating controls for exposed systems.
- Track exceptions and retest remediated assets.
Evidence notes
The CVE Program and NVD provide official records of this vulnerability. Red Hat has released advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257 related to this issue. Bugzilla entry RHBZ#2536953 tracks the issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93564 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93564
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93564 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93564
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-co
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93564.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69440
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69470
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:70257
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93564
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.