PatchSiren cyber security CVE debrief
CVE-2026-93573 Red Hat CVE debrief
A vulnerability in Netty's HTTP/1.1 decoder allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers. This can lead to HTTP request smuggling, enabling attackers to bypass security controls or desynchronize request processing. The vulnerability is particularly relevant to defenders responsible for Netty-based applications, especially those using Red Hat build of Quarkus, Red Hat AMQ Broker, and Red Hat AMQ Clients. Affected versions and remediation details require verification from official sources.
- Vendor
- Red Hat
- Product
- Red Hat build of Quarkus 3.27.5.SP2
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for Netty-based applications, particularly those using Red Hat build of Quarkus, Red Hat AMQ Broker, Red Hat AMQ Clients, and other affected products, should assess exposure and prioritize remediation.
Why it matters
Defenders should care about CVE-2026-93573 because it allows remote attackers to bypass security controls and desynchronize request processing in Netty-based applications, particularly those using Red Hat products. Affected versions and remediation details are not specified, requiring verification from official sources.
- Potential HTTP request smuggling attacks
- Bypassing of security controls
- Desynchronization of request processing
- Requests processed in unintended contexts
Technical summary
The vulnerability in Netty's HTTP/1.1 decoder allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.
Defensive priority
Defenders should prioritize verifying affected versions and applying vendor remediation to prevent potential HTTP request smuggling attacks.
Recommended defensive actions
- Verify affected versions of Netty and dependent products
- Apply vendor remediation from Red Hat for affected products
- Monitor for potential HTTP request smuggling attacks
- Review and update security controls to detect and prevent request smuggling
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but do not specify affected or fixed versions. Vendor advisories from Red Hat are available for affected products. Defenders should verify the affected scope, severity, and vendor guidance by reviewing the official advisory or CVE record. They should also check for potential HTTP request smuggling attacks and review compensating controls for exposed systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93573 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93573
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93573 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93573
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked validation
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93573.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69440
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69470
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93573
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.