PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93573 Red Hat CVE debrief

A vulnerability in Netty's HTTP/1.1 decoder allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers. This can lead to HTTP request smuggling, enabling attackers to bypass security controls or desynchronize request processing. The vulnerability is particularly relevant to defenders responsible for Netty-based applications, especially those using Red Hat build of Quarkus, Red Hat AMQ Broker, and Red Hat AMQ Clients. Affected versions and remediation details require verification from official sources.

Vendor
Red Hat
Product
Red Hat build of Quarkus 3.27.5.SP2
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-10-09
Advisory published
2026-09-18
Advisory updated
2026-10-09

Who should care

Defenders responsible for Netty-based applications, particularly those using Red Hat build of Quarkus, Red Hat AMQ Broker, Red Hat AMQ Clients, and other affected products, should assess exposure and prioritize remediation.

Why it matters

Defenders should care about CVE-2026-93573 because it allows remote attackers to bypass security controls and desynchronize request processing in Netty-based applications, particularly those using Red Hat products. Affected versions and remediation details are not specified, requiring verification from official sources.

  • Potential HTTP request smuggling attacks
  • Bypassing of security controls
  • Desynchronization of request processing
  • Requests processed in unintended contexts

Technical summary

The vulnerability in Netty's HTTP/1.1 decoder allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.

Defensive priority

Defenders should prioritize verifying affected versions and applying vendor remediation to prevent potential HTTP request smuggling attacks.

Recommended defensive actions

  • Verify affected versions of Netty and dependent products
  • Apply vendor remediation from Red Hat for affected products
  • Monitor for potential HTTP request smuggling attacks
  • Review and update security controls to detect and prevent request smuggling
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but do not specify affected or fixed versions. Vendor advisories from Red Hat are available for affected products. Defenders should verify the affected scope, severity, and vendor guidance by reviewing the official advisory or CVE record. They should also check for potential HTTP request smuggling attacks and review compensating controls for exposed systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93573 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93573

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93573 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93573

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked validation

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93573.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69440

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69470

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-93573

    Supplemental source - vdb-entry, x_refsource_REDHAT

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.