PatchSiren cyber security CVE debrief
CVE-2026-93569 Red Hat CVE debrief
A vulnerability in Netty's HTTP/1 to HTTP/2 conversion process allows a remote unauthenticated attacker to bypass security controls in Netty-based proxies or gateways. This flaw can lead to unauthorized access, cache poisoning, or misrouting of requests. The vulnerability arises when an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, causing Netty to incorrectly prioritize the Host header for the HTTP/2 :authority field, discarding the original request-target authority.
- Vendor
- Red Hat
- Product
- Red Hat Build of Apache Camel 3.33.3.SP2
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-10-09
Who should care
Defenders of Netty-based proxies, gateways, and systems using affected Red Hat products should assess exposure and apply remediation. Relevant roles include security teams, network administrators, and DevOps engineers.
Why it matters
CVE-2026-93569 allows a remote unauthenticated attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests. Defenders should prioritize verifying affected systems, reviewing proxy configurations, and applying vendor remediation.
- Potential unauthorized access to sensitive data or systems
- Cache poisoning or misrouting of requests
- Bypassing of security controls in Netty-based proxies or gateways
- Verification of affected systems and proxy configurations
Technical summary
A flaw in Netty's HTTP/1 to HTTP/2 conversion process allows a remote unauthenticated attacker to override the request-target authority. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.
Defensive priority
Defenders should prioritize verifying affected Netty-based systems, reviewing proxy and gateway configurations, and applying vendor remediation.
Recommended defensive actions
- Verify affected Netty-based systems and proxy configurations
- Review and update security controls for HTTP/1 to HTTP/2 conversion
- Apply vendor remediation and patches
- Monitor for suspicious activity and misrouting of requests
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE Program and NVD provide official records of the vulnerability. Red Hat provides supplemental advisories and errata for affected products. Defenders should verify affected Netty-based systems, review proxy configurations, and apply vendor remediation. The vulnerability's impact on security controls and potential for unauthorized access necessitates thorough review and mitigation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93569 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93569
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93569 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93569
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authorit
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93569.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69440
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69470
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:70257
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93569
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.