PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93568 Red Hat CVE debrief

A flaw in Netty allows remote attackers to exploit HTTP/2 or HTTP/3 Extended CONNECT requests, leading to loss of critical protocol and path information. This can enable attackers to bypass security policies in applications relying on Netty for HTTP/2 or HTTP/3 communication, resulting in integrity loss. The vulnerability affects Netty's HTTP-object conversion path, which incorrectly processes these requests as regular HTTP/1.1 CONNECT requests. Defenders should assess exposure, verify affected versions, and apply remediation to prevent potential integrity loss.

Vendor
Red Hat
Product
Red Hat Build of Apache Camel 3.33.3.SP2
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-10-09
Advisory published
2026-09-18
Advisory updated
2026-10-09

Who should care

Defenders of systems using Netty for HTTP/2 or HTTP/3 communication, especially those with routing or authorization logic, should assess exposure and prioritize remediation. This includes verifying affected versions, applying vendor remediation, and reviewing compensating controls for exposed systems. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented.

Why it matters

CVE-2026-93568 allows remote attackers to bypass security policies in Netty-based applications, potentially leading to integrity loss. Defenders should assess exposure, verify affected versions, and apply remediation.

  • Bypass of security policies such as routing or authorization logic
  • Potential integrity loss in applications relying on Netty for HTTP/2 or HTTP/3 communication
  • Need to verify affected versions and apply vendor remediation
  • Possible exposure in systems with unpatched Netty implementations

Technical summary

Netty's HTTP-object conversion path incorrectly processes HTTP/2 or HTTP/3 Extended CONNECT requests as regular HTTP/1.1 CONNECT requests, leading to loss of critical protocol and path information. This misinterpretation can allow attackers to bypass security policies, such as routing or authorization logic, in applications that rely on Netty for HTTP/2 or HTTP/3 communication. The vulnerability affects Netty's handling of Extended CONNECT requests, which can result in integrity loss if exploited. Defenders should verify affected versions and apply vendor remediation to prevent potential integrity loss.

Defensive priority

Defenders should prioritize assessing exposure in systems using Netty for HTTP/2 or HTTP/3 communication, especially those with routing or authorization logic. Verify affected versions and apply vendor remediation.

Recommended defensive actions

  • Assess exposure in systems using Netty for HTTP/2 or HTTP/3 communication
  • Verify affected versions and apply vendor remediation
  • Review routing and authorization logic for potential bypass vulnerabilities
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. Red Hat provides supplemental advisories for affected products. The vulnerability has been publicly disclosed and defenders should verify affected versions and apply vendor remediation. The CVE record was published on 2026-09-18T14:34:04.546Z and has not been modified since then.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93568 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93568

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93568 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93568

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended connec

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93568.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69440

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69470

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:70257

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-93568

    Supplemental source - vdb-entry, x_refsource_REDHAT

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.