PatchSiren cyber security CVE debrief
CVE-2026-93574 Red Hat CVE debrief
A flaw in Netty's `netty-codec-http` component can allow a remote attacker to exploit HTTP request smuggling via a specially crafted HTTP/1.1 chunk-size token with post-digit whitespace. This incorrect parsing of the chunk size can lead to HTTP request smuggling, potentially allowing an attacker to bypass security controls or access unauthorized resources in proxy/backend deployments.
- Vendor
- Red Hat
- Product
- Red Hat build of Quarkus 3.27.5.SP2
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for proxy/backend deployments using Netty's `netty-codec-http` component should assess exposure and verify the presence of affected components in their environment.
Why it matters
CVE-2026-93574 allows for HTTP request smuggling in Netty's `netty-codec-http` component, potentially impacting proxy/backend deployments. Defenders should verify exposure, assess the presence of affected components, and prioritize applying vendor advisories.
- Potential bypass of security controls
- Possible access to unauthorized resources
- Need for verification of affected Netty components
- Priority for applying vendor advisories
Technical summary
The Netty `netty-codec-http` component incorrectly parses HTTP/1.1 chunk-size tokens with post-digit whitespace, allowing for HTTP request smuggling. This can occur in proxy/backend deployments, potentially enabling attackers to bypass security controls or access unauthorized resources. The vulnerability is caused by a flaw in the parsing of chunk-size tokens, which can lead to incorrect interpretation of HTTP requests. Defenders should prioritize verifying the presence of affected Netty components in their environment and assess exposure to proxy/backend deployments.
Defensive priority
Defenders should prioritize verifying the presence of affected Netty components in their environment and assess exposure to proxy/backend deployments.
Recommended defensive actions
- Verify the presence of affected Netty components in the environment
- Assess exposure to proxy/backend deployments
- Review and apply vendor advisories (RHSA-2026:69440, RHSA-2026:69470)
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE Program and NVD provide official records of the vulnerability. Red Hat provides supplemental advisories (RHSA-2026:69440, RHSA-2026:69470) and a security page for CVE-2026-93574. Defenders should verify the presence of affected Netty components, assess exposure, and prioritize applying vendor advisories. The vulnerability allows for HTTP request smuggling, potentially impacting proxy/backend deployments. Evidence is limited to CVE Program and NVD records, and defenders should review these sources for further details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93574 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93574
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93574 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93574
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Io.netty/netty-codec-http: netty: http request smuggling via post-digit whitespace in chunk-size
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93574.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69440
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:69470
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93574
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.