PatchSiren cyber security CVE debrief
CVE-2026-93568 Red Hat CVE debrief
A flaw in Netty allows remote attackers to exploit HTTP/2 or HTTP/3 Extended CONNECT requests, leading to loss of critical protocol and path information. This can enable attackers to bypass security policies in applications relying on Netty for HTTP/2 or HTTP/3 communication, resulting in integrity loss. The vulnerability affects Netty's HTTP-object conversion path, which incorrectly processes these requests as regular HTTP/1.1 CONNECT requests. Defenders should assess exposure, verify affected versions, and apply remediation to prevent potential integrity loss.
- Vendor
- Red Hat
- Product
- Red Hat Build of Apache Camel 3.33.3.SP2
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-10-09
Who should care
Defenders of systems using Netty for HTTP/2 or HTTP/3 communication, especially those with routing or authorization logic, should assess exposure and prioritize remediation. This includes verifying affected versions, applying vendor remediation, and reviewing compensating controls for exposed systems. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented.
Why it matters
CVE-2026-93568 allows remote attackers to bypass security policies in Netty-based applications, potentially leading to integrity loss. Defenders should assess exposure, verify affected versions, and apply remediation.
- Bypass of security policies such as routing or authorization logic
- Potential integrity loss in applications relying on Netty for HTTP/2 or HTTP/3 communication
- Need to verify affected versions and apply vendor remediation
- Possible exposure in systems with unpatched Netty implementations
Technical summary
Netty's HTTP-object conversion path incorrectly processes HTTP/2 or HTTP/3 Extended CONNECT requests as regular HTTP/1.1 CONNECT requests, leading to loss of critical protocol and path information. This misinterpretation can allow attackers to bypass security policies, such as routing or authorization logic, in applications that rely on Netty for HTTP/2 or HTTP/3 communication. The vulnerability affects Netty's handling of Extended CONNECT requests, which can result in integrity loss if exploited. Defenders should verify affected versions and apply vendor remediation to prevent potential integrity loss.
Defensive priority
Defenders should prioritize assessing exposure in systems using Netty for HTTP/2 or HTTP/3 communication, especially those with routing or authorization logic. Verify affected versions and apply vendor remediation.
Recommended defensive actions
- Assess exposure in systems using Netty for HTTP/2 or HTTP/3 communication
- Verify affected versions and apply vendor remediation
- Review routing and authorization logic for potential bypass vulnerabilities
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. Red Hat provides supplemental advisories for affected products. The vulnerability has been publicly disclosed and defenders should verify affected versions and apply vendor remediation. The CVE record was published on 2026-09-18T14:34:04.546Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93568 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93568
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93568 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93568
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended connec
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93568.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69440
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69470
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:70257
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93568
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.