PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93574 Red Hat CVE debrief

A flaw in Netty's `netty-codec-http` component can allow a remote attacker to exploit HTTP request smuggling via a specially crafted HTTP/1.1 chunk-size token with post-digit whitespace. This incorrect parsing of the chunk size can lead to HTTP request smuggling, potentially allowing an attacker to bypass security controls or access unauthorized resources in proxy/backend deployments.

Vendor
Red Hat
Product
Red Hat build of Quarkus 3.27.5.SP2
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-10-09
Advisory published
2026-09-18
Advisory updated
2026-10-09

Who should care

Defenders responsible for proxy/backend deployments using Netty's `netty-codec-http` component should assess exposure and verify the presence of affected components in their environment.

Why it matters

CVE-2026-93574 allows for HTTP request smuggling in Netty's `netty-codec-http` component, potentially impacting proxy/backend deployments. Defenders should verify exposure, assess the presence of affected components, and prioritize applying vendor advisories.

  • Potential bypass of security controls
  • Possible access to unauthorized resources
  • Need for verification of affected Netty components
  • Priority for applying vendor advisories

Technical summary

The Netty `netty-codec-http` component incorrectly parses HTTP/1.1 chunk-size tokens with post-digit whitespace, allowing for HTTP request smuggling. This can occur in proxy/backend deployments, potentially enabling attackers to bypass security controls or access unauthorized resources. The vulnerability is caused by a flaw in the parsing of chunk-size tokens, which can lead to incorrect interpretation of HTTP requests. Defenders should prioritize verifying the presence of affected Netty components in their environment and assess exposure to proxy/backend deployments.

Defensive priority

Defenders should prioritize verifying the presence of affected Netty components in their environment and assess exposure to proxy/backend deployments.

Recommended defensive actions

  • Verify the presence of affected Netty components in the environment
  • Assess exposure to proxy/backend deployments
  • Review and apply vendor advisories (RHSA-2026:69440, RHSA-2026:69470)
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE Program and NVD provide official records of the vulnerability. Red Hat provides supplemental advisories (RHSA-2026:69440, RHSA-2026:69470) and a security page for CVE-2026-93574. Defenders should verify the presence of affected Netty components, assess exposure, and prioritize applying vendor advisories. The vulnerability allows for HTTP request smuggling, potentially impacting proxy/backend deployments. Evidence is limited to CVE Program and NVD records, and defenders should review these sources for further details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93574 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93574

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93574 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93574

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Io.netty/netty-codec-http: netty: http request smuggling via post-digit whitespace in chunk-size

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93574.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69440

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:69470

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-93574

    Supplemental source - vdb-entry, x_refsource_REDHAT

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.