PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93569 Red Hat CVE debrief

A vulnerability in Netty's HTTP/1 to HTTP/2 conversion process allows a remote unauthenticated attacker to bypass security controls in Netty-based proxies or gateways. This flaw can lead to unauthorized access, cache poisoning, or misrouting of requests. The vulnerability arises when an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, causing Netty to incorrectly prioritize the Host header for the HTTP/2 :authority field, discarding the original request-target authority.

Vendor
Red Hat
Product
Red Hat Build of Apache Camel 3.33.3.SP2
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-10-09
Advisory published
2026-09-18
Advisory updated
2026-10-09

Who should care

Defenders of Netty-based proxies, gateways, and systems using affected Red Hat products should assess exposure and apply remediation. Relevant roles include security teams, network administrators, and DevOps engineers.

Why it matters

CVE-2026-93569 allows a remote unauthenticated attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests. Defenders should prioritize verifying affected systems, reviewing proxy configurations, and applying vendor remediation.

  • Potential unauthorized access to sensitive data or systems
  • Cache poisoning or misrouting of requests
  • Bypassing of security controls in Netty-based proxies or gateways
  • Verification of affected systems and proxy configurations

Technical summary

A flaw in Netty's HTTP/1 to HTTP/2 conversion process allows a remote unauthenticated attacker to override the request-target authority. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.

Defensive priority

Defenders should prioritize verifying affected Netty-based systems, reviewing proxy and gateway configurations, and applying vendor remediation.

Recommended defensive actions

  • Verify affected Netty-based systems and proxy configurations
  • Review and update security controls for HTTP/1 to HTTP/2 conversion
  • Apply vendor remediation and patches
  • Monitor for suspicious activity and misrouting of requests
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE Program and NVD provide official records of the vulnerability. Red Hat provides supplemental advisories and errata for affected products. Defenders should verify affected Netty-based systems, review proxy configurations, and apply vendor remediation. The vulnerability's impact on security controls and potential for unauthorized access necessitates thorough review and mitigation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93569 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93569

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93569 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93569

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authorit

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93569.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69440

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69470

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:70257

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-93569

    Supplemental source - vdb-entry, x_refsource_REDHAT

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.