PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93565 Red Hat CVE debrief

A vulnerability in Netty's RtspDecoder allows for method-token smuggling via trailing control bytes in RTSP requests. This flaw can be exploited by a remote attacker to bypass method-based access controls and launder malicious requests through Netty-based RTSP proxies. The vulnerability affects Netty-based applications using RtspDecoder, and defenders should assess exposure and potential impact. The CVE Program and NVD provide official records of the vulnerability, and Red Hat has released advisories regarding the vulnerability.

Vendor
Red Hat
Product
Red Hat Build of Apache Camel 3.33.3.SP2
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-10-09
Advisory published
2026-09-18
Advisory updated
2026-10-09

Who should care

Defenders responsible for Netty-based applications, especially those using RtspDecoder, should assess exposure and potential impact. They should verify exposure, assess the impact of potential method-token smuggling attacks, and apply patches or updates provided by vendors. Additionally, they should monitor for suspicious RTSP requests and review compensating controls for exposed systems.

Why it matters

CVE-2026-93565 allows for method-token smuggling in Netty's RtspDecoder, potentially bypassing access controls and enabling malicious requests. Defenders should verify exposure, assess impact, and apply patches.

  • Bypassing method-based access controls
  • Laundering malicious requests through Netty-based RTSP proxies
  • Potential for unauthorized access or data breaches
  • Need for verification of affected versions and application of patches

Technical summary

The RtspDecoder in Netty incorrectly strips trailing control bytes from method tokens in RTSP requests, allowing for method-token smuggling attacks. This vulnerability can be exploited by a remote attacker to bypass method-based access controls and launder malicious requests through Netty-based RTSP proxies. The vulnerability affects Netty-based applications using RtspDecoder, and defenders should assess exposure and potential impact. The CVE Program and NVD provide official records of the vulnerability, and Red Hat has released advisories regarding the vulnerability.

Defensive priority

Defenders should prioritize verifying exposure in Netty-based applications, especially those using RtspDecoder, and assess the impact of potential method-token smuggling attacks.

Recommended defensive actions

  • Verify exposure in Netty-based applications using RtspDecoder
  • Assess the impact of potential method-token smuggling attacks
  • Apply patches or updates provided by vendors
  • Monitor for suspicious RTSP requests
  • Review compensating controls for exposed systems
  • Track exceptions and retest remediated assets
  • Check relevant monitoring, detection, and logs for exposed assets

Evidence notes

The CVE Program and NVD provide official records of the vulnerability. Red Hat has released advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257 regarding the vulnerability. Defenders should verify exposure in Netty-based applications, especially those using RtspDecoder, and assess the impact of potential method-token smuggling attacks. The vulnerability allows for method-token smuggling in RTSP requests, potentially bypassing access controls and enabling malicious requests.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93565 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93565

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93565 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93565

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93565.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69440

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69470

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:70257

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-93565

    Supplemental source - vdb-entry, x_refsource_REDHAT

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.