PatchSiren cyber security CVE debrief
CVE-2026-93565 Red Hat CVE debrief
A vulnerability in Netty's RtspDecoder allows for method-token smuggling via trailing control bytes in RTSP requests. This flaw can be exploited by a remote attacker to bypass method-based access controls and launder malicious requests through Netty-based RTSP proxies. The vulnerability affects Netty-based applications using RtspDecoder, and defenders should assess exposure and potential impact. The CVE Program and NVD provide official records of the vulnerability, and Red Hat has released advisories regarding the vulnerability.
- Vendor
- Red Hat
- Product
- Red Hat Build of Apache Camel 3.33.3.SP2
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for Netty-based applications, especially those using RtspDecoder, should assess exposure and potential impact. They should verify exposure, assess the impact of potential method-token smuggling attacks, and apply patches or updates provided by vendors. Additionally, they should monitor for suspicious RTSP requests and review compensating controls for exposed systems.
Why it matters
CVE-2026-93565 allows for method-token smuggling in Netty's RtspDecoder, potentially bypassing access controls and enabling malicious requests. Defenders should verify exposure, assess impact, and apply patches.
- Bypassing method-based access controls
- Laundering malicious requests through Netty-based RTSP proxies
- Potential for unauthorized access or data breaches
- Need for verification of affected versions and application of patches
Technical summary
The RtspDecoder in Netty incorrectly strips trailing control bytes from method tokens in RTSP requests, allowing for method-token smuggling attacks. This vulnerability can be exploited by a remote attacker to bypass method-based access controls and launder malicious requests through Netty-based RTSP proxies. The vulnerability affects Netty-based applications using RtspDecoder, and defenders should assess exposure and potential impact. The CVE Program and NVD provide official records of the vulnerability, and Red Hat has released advisories regarding the vulnerability.
Defensive priority
Defenders should prioritize verifying exposure in Netty-based applications, especially those using RtspDecoder, and assess the impact of potential method-token smuggling attacks.
Recommended defensive actions
- Verify exposure in Netty-based applications using RtspDecoder
- Assess the impact of potential method-token smuggling attacks
- Apply patches or updates provided by vendors
- Monitor for suspicious RTSP requests
- Review compensating controls for exposed systems
- Track exceptions and retest remediated assets
- Check relevant monitoring, detection, and logs for exposed assets
Evidence notes
The CVE Program and NVD provide official records of the vulnerability. Red Hat has released advisories RHSA-2026:69440, RHSA-2026:69470, and RHSA-2026:70257 regarding the vulnerability. Defenders should verify exposure in Netty-based applications, especially those using RtspDecoder, and assess the impact of potential method-token smuggling attacks. The vulnerability allows for method-token smuggling in RTSP requests, potentially bypassing access controls and enabling malicious requests.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93565 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93565
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93565 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93565
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93565.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69440
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69470
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:70257
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93565
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.