PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93564 Red Hat CVE debrief

A reference-count leak in the HAProxy PROXY-v2 message decoder in Netty allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers, potentially leading to memory exhaustion and a Denial of Service (DoS) for the affected system. This issue affects multiple Red Hat products that utilize Netty. The vulnerability has a high CVSS score of 7.5 and is considered HIGH severity. The CVE Program and NVD provide official records of this vulnerability. Red Hat has released advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257 related to this issue.

Vendor
Red Hat
Product
Red Hat Build of Apache Camel 3.33.3.SP2
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-10-09
Advisory published
2026-09-18
Advisory updated
2026-10-09

Who should care

Defenders responsible for Red Hat products that utilize Netty, especially those with internet-exposed services, should assess their exposure and prioritize updating vulnerable versions of netty-codec-haproxy.

Why it matters

CVE-2026-93564 is a high-severity vulnerability in Netty's HAProxy PROXY-v2 message decoder that can lead to a Denial of Service (DoS). Defenders should prioritize verifying exposure in Red Hat products, especially those with internet-exposed services, and update vulnerable versions of netty-codec-haproxy as soon as available.

  • Memory exhaustion leading to Denial of Service (DoS)
  • Potential for remote, unauthenticated exploitation
  • Affected systems require immediate version updates for netty-codec-haproxy
  • Verification of exposure and remediation are critical for systems with internet-exposed services

Technical summary

The vulnerability exists in the netty-codec-haproxy package, which is used by multiple Red Hat products. A remote, unauthenticated attacker can exploit this by sending specially crafted PROXY-protocol v2 headers, potentially leading to memory exhaustion and a Denial of Service (DoS). The issue arises from a reference-count leak in the HAProxy PROXY-v2 message decoder. Defenders should prioritize verifying exposure in Red Hat products that use Netty, especially those with internet-exposed services. They should assess if their systems are using vulnerable versions of netty-codec-haproxy and update to patched versions as soon as available.

Defensive priority

Defenders should prioritize verifying exposure in Red Hat products that use Netty, especially those with internet-exposed services. They should assess if their systems are using vulnerable versions of netty-codec-haproxy and update to patched versions as soon as available.

Recommended defensive actions

  • Verify if your Red Hat products are using vulnerable versions of netty-codec-haproxy.
  • Update to patched versions of netty-codec-haproxy as soon as available.
  • Monitor systems for unusual memory usage or DoS symptoms.
  • Review and apply Red Hat advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257.
  • Perform a thorough review of system configurations and internet-exposed services.
  • Consider implementing compensating controls for exposed systems.
  • Track exceptions and retest remediated assets.

Evidence notes

The CVE Program and NVD provide official records of this vulnerability. Red Hat has released advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257 related to this issue. Bugzilla entry RHBZ#2536953 tracks the issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93564 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93564

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93564 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93564

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-co

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93564.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69440

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69470

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:70257

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-93564

    Supplemental source - vdb-entry, x_refsource_REDHAT

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.