{"id":"CVE-2026-56746","title":"io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746)","summary":"A flaw was found in Netty, a network application framework. A remote attacker can bypass security controls in the `CorsHandler` component by sending a specially crafted request with a null origin header. This bypasses the intended access r…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvssSource":"vendor","cwe":["CWE-807","CWE-284"],"vendor":"Red Hat","product":"Red Hat OpenShift Dev Spaces 3.30","affected":["openshift_serverless","amq_clients","build_of_apache_camel_hawtio 4","build_of_apache_camel_4_for_quarkus 3","build_of_apicurio_registry 3","build_of_debezium 3","build_of_keycloak","enterprise_linux_ai_rhel_ai 3","jboss_enterprise_application_platform 7","jboss_enterprise_application_platform 8","openshift_ai_rhoai","openshift_dev_spaces","single_sign_on 7","streams_for_apache_kafka 2","cryostat_4_on_rhel 9","amq_broker 7.13.6","amq_broker 7.14.1","build_of_apache_camel_4_18_for_quarkus 3.33","data_grid 8.6.3","openshift_ai 2.25","openshift_dev_spaces 3.30","build_of_apache_camel_4_18_3_for_spring_boot 3.5.16","build_of_quarkus 3.27.4.SP3","build_of_quarkus 3.33.2.SP3","streams_for_apache_kafka 3.2.1"],"patched":["cryostat_4_on_rhel 9","amq_broker 7.13.6","amq_broker 7.14.1","build_of_apache_camel_4_18_for_quarkus 3.33","data_grid 8.6.3","openshift_ai 2.25","openshift_dev_spaces 3.30","build_of_apache_camel_4_18_3_for_spring_boot 3.5.16","build_of_quarkus 3.27.4.SP3","build_of_quarkus 3.33.2.SP3","streams_for_apache_kafka 3.2.1"],"published":"2026-07-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:20:09+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56746.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56746.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-56746"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2505422"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-56746"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56746"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"},{"url":"https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"},{"url":"https://access.redhat.com/errata/RHSA-2026:68333"},{"url":"https://access.redhat.com/errata/RHSA-2026:66545"},{"url":"https://access.redhat.com/errata/RHSA-2026:66488"},{"url":"https://access.redhat.com/errata/RHSA-2026:48118"},{"url":"https://access.redhat.com/errata/RHSA-2026:69296"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"url":"https://access.redhat.com/errata/RHSA-2026:62260"},{"url":"https://access.redhat.com/errata/RHSA-2026:68754"},{"url":"https://access.redhat.com/errata/RHSA-2026:54622"},{"url":"https://access.redhat.com/errata/RHSA-2026:47189"},{"url":"https://access.redhat.com/errata/RHSA-2026:47172"},{"url":"https://access.redhat.com/errata/RHSA-2026:54435"},{"url":"https://github.com/advisories/GHSA-6cqp-g7gg-8hr5"}],"tags":["csaf","vex","red-hat","ghsa","maven"],"epss":0.00379,"epssPercentile":0.31681,"aliases":["GHSA-6cqp-g7gg-8hr5"],"ecosystem":"maven","scores":{"vendor":7.5,"ghsa":6.5},"ingestedAt":"2026-07-22T22:06:57.842Z","slug":"CVE-2026-56746","body":"## Overview\n\nA flaw was found in Netty, a network application framework. A remote attacker can bypass security controls in the `CorsHandler` component by sending a specially crafted request with a null origin header. This bypasses the intended access restrictions, allowing unauthorized requests to reach the backend application. This could lead to a compromise of data integrity by allowing unauthorized actions.\n\n## Vendor advisories\n\n- **RHSA-2026:68333** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68333)\n- **RHSA-2026:66545** · Red Hat · fixed in: Red Hat AMQ Broker 7.13.6 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66545)\n- **RHSA-2026:66488** · Red Hat · fixed in: Red Hat AMQ Broker 7.14.1 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66488)\n- **RHSA-2026:48118** · Red Hat · fixed in: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48118)\n- **RHSA-2026:69296** · Red Hat · fixed in: Red Hat Data Grid 8.6.3 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69296)\n- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)\n- **RHSA-2026:62260** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62260)\n- **RHSA-2026:68754** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68754)\n- **RHSA-2026:54622** · Red Hat · fixed in: Red Hat build of Apache Camel 4.18.3 for Spring Boot 3.5.16 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54622)\n- **RHSA-2026:47189** · Red Hat · fixed in: Red Hat build of Quarkus 3.27.4.SP3 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:47189)\n- **RHSA-2026:47172** · Red Hat · fixed in: Red Hat build of Quarkus 3.33.2.SP3 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:47172)\n- **Red Hat VEX** · Important · affected: OpenShift Serverless, Red Hat AMQ Clients, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, … · no fix planned: Red Hat Single Sign-On 7, Red Hat build of Debezium 3, Red Hat JBoss Enterprise Application Platform 7, OpenShift Serverless, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56746.json)\n- **RHSA-2026:54435** · Red Hat · fixed in: Streams for Apache Kafka 3.2.1 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54435)\n\n**io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header** — rated Important by Red Hat. Released 2026-07-21, updated 2026-09-21.\n\nAffected:\n\n- OpenShift Serverless\n- Red Hat AMQ Clients\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apache Camel 4 for Quarkus 3\n- Red Hat build of Apicurio Registry 3\n- Red Hat build of Debezium 3\n- Red Hat Build of Keycloak\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat JBoss Enterprise Application Platform 7\n- Red Hat JBoss Enterprise Application Platform 8\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Dev Spaces\n- Red Hat Single Sign-On 7\n- streams for Apache Kafka 2\n\nFixed:\n\n- Cryostat 4 on RHEL 9\n- Red Hat AMQ Broker 7.13.6\n- Red Hat AMQ Broker 7.14.1\n- Red Hat Build of Apache Camel 4.18 for Quarkus 3.33\n- Red Hat Data Grid 8.6.3\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift Dev Spaces 3.30\n- Red Hat build of Apache Camel 4.18.3 for Spring Boot 3.5.16\n- Red Hat build of Quarkus 3.27.4.SP3\n- Red Hat build of Quarkus 3.33.2.SP3\n- Streams for Apache Kafka 3.2.1\n\nNo fix planned:\n\n- Red Hat Single Sign-On 7\n- Red Hat build of Debezium 3\n- Red Hat JBoss Enterprise Application Platform 7\n- OpenShift Serverless\n- Red Hat AMQ Clients\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apache Camel 4 for Quarkus 3\n- Red Hat build of Apicurio Registry 3\n- Red Hat Build of Keycloak\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat JBoss Enterprise Application Platform 8\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Dev Spaces\n- streams for Apache Kafka 2\n\nNot affected:\n\n- Cryostat 4 on RHEL 9\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift Dev Spaces 3.30\n- Red Hat JBoss Enterprise Application Platform Expansion Pack\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333\nBefore applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.\n\nThe References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66545\nBefore applying the update, back up your existing installation, including all applications, configuration files, databases and database settings.\n\nThe References section of this erratum contains a download link (you must log in to download the update). https://access.redhat.com/errata/RHSA-2026:66488\n\nWorkarounds / mitigations:\n\n- If CORS short-circuit functionality is not required, disable the shortCircuit() configuration in the CorsHandler. Alternatively, implement application-level origin validation to reject requests with null Origin headers. A web application firewall (WAF) can also be configured to block requests with null or missing Origin headers.\n\n## Package advisory (CVE-2026-56746)\n\nAffected packages:\n\n- `io.netty:netty-codec-http >= 4.2.0.Final, < 4.2.16.Final`\n- `io.netty:netty-codec-http < 4.1.136.Final`\n\nPatched in:\n\n- `io.netty:netty-codec-http 4.2.16.Final`\n- `io.netty:netty-codec-http 4.1.136.Final`\n\nSource: https://github.com/advisories/GHSA-6cqp-g7gg-8hr5","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201791,"id":"CVE-2026-56746","ts":1789399725598,"field":"cvss","old":"6.5","new":"7.5"},{"seq":201790,"id":"CVE-2026-56746","ts":1789399725598,"field":"severity","old":"medium","new":"high"},{"seq":200521,"id":"CVE-2026-56746","ts":1789397373563,"field":"cvss","old":"7.5","new":"6.5"},{"seq":200520,"id":"CVE-2026-56746","ts":1789397373563,"field":"severity","old":"high","new":"medium"},{"seq":198438,"id":"CVE-2026-56746","ts":1789391968550,"field":"cvss","old":"6.5","new":"7.5"},{"seq":198437,"id":"CVE-2026-56746","ts":1789391968550,"field":"severity","old":"medium","new":"high"},{"seq":196231,"id":"CVE-2026-56746","ts":1789383584995,"field":"cvss","old":"7.5","new":"6.5"},{"seq":196230,"id":"CVE-2026-56746","ts":1789383584995,"field":"severity","old":"high","new":"medium"},{"seq":195160,"id":"CVE-2026-56746","ts":1789380474799,"field":"cvss","old":"6.5","new":"7.5"},{"seq":195159,"id":"CVE-2026-56746","ts":1789380474799,"field":"severity","old":"medium","new":"high"},{"seq":193947,"id":"CVE-2026-56746","ts":1789378514177,"field":"cvss","old":"7.5","new":"6.5"},{"seq":193946,"id":"CVE-2026-56746","ts":1789378514177,"field":"severity","old":"high","new":"medium"},{"seq":192734,"id":"CVE-2026-56746","ts":1789376406861,"field":"cvss","old":"6.5","new":"7.5"},{"seq":192733,"id":"CVE-2026-56746","ts":1789376406861,"field":"severity","old":"medium","new":"high"},{"seq":191521,"id":"CVE-2026-56746","ts":1789373419477,"field":"cvss","old":"7.5","new":"6.5"},{"seq":191520,"id":"CVE-2026-56746","ts":1789373419477,"field":"severity","old":"high","new":"medium"},{"seq":190306,"id":"CVE-2026-56746","ts":1789369298200,"field":"cvss","old":"6.5","new":"7.5"},{"seq":190305,"id":"CVE-2026-56746","ts":1789369298200,"field":"severity","old":"medium","new":"high"},{"seq":189093,"id":"CVE-2026-56746","ts":1789368266746,"field":"cvss","old":"7.5","new":"6.5"},{"seq":189092,"id":"CVE-2026-56746","ts":1789368266746,"field":"severity","old":"high","new":"medium"},{"seq":187876,"id":"CVE-2026-56746","ts":1789365143093,"field":"cvss","old":"6.5","new":"7.5"},{"seq":187875,"id":"CVE-2026-56746","ts":1789365143093,"field":"severity","old":"medium","new":"high"},{"seq":186663,"id":"CVE-2026-56746","ts":1789363271163,"field":"cvss","old":"7.5","new":"6.5"},{"seq":186662,"id":"CVE-2026-56746","ts":1789363271163,"field":"severity","old":"high","new":"medium"},{"seq":185449,"id":"CVE-2026-56746","ts":1789361101044,"field":"cvss","old":"6.5","new":"7.5"},{"seq":185448,"id":"CVE-2026-56746","ts":1789361101044,"field":"severity","old":"medium","new":"high"},{"seq":184236,"id":"CVE-2026-56746","ts":1789358155453,"field":"cvss","old":"7.5","new":"6.5"},{"seq":184235,"id":"CVE-2026-56746","ts":1789358155453,"field":"severity","old":"high","new":"medium"},{"seq":182487,"id":"CVE-2026-56746","ts":1789354222229,"field":"cvss","old":"6.5","new":"7.5"},{"seq":182486,"id":"CVE-2026-56746","ts":1789354222229,"field":"severity","old":"medium","new":"high"},{"seq":181280,"id":"CVE-2026-56746","ts":1789353120364,"field":"cvss","old":"7.5","new":"6.5"},{"seq":181279,"id":"CVE-2026-56746","ts":1789353120364,"field":"severity","old":"high","new":"medium"},{"seq":180073,"id":"CVE-2026-56746","ts":1789350168874,"field":"cvss","old":"6.5","new":"7.5"},{"seq":180072,"id":"CVE-2026-56746","ts":1789350168874,"field":"severity","old":"medium","new":"high"},{"seq":178866,"id":"CVE-2026-56746","ts":1789348100970,"field":"cvss","old":"7.5","new":"6.5"},{"seq":178865,"id":"CVE-2026-56746","ts":1789348100970,"field":"severity","old":"high","new":"medium"},{"seq":177659,"id":"CVE-2026-56746","ts":1789346277359,"field":"cvss","old":"6.5","new":"7.5"},{"seq":177658,"id":"CVE-2026-56746","ts":1789346277359,"field":"severity","old":"medium","new":"high"},{"seq":176452,"id":"CVE-2026-56746","ts":1789343018561,"field":"cvss","old":"7.5","new":"6.5"},{"seq":176451,"id":"CVE-2026-56746","ts":1789343018561,"field":"severity","old":"high","new":"medium"},{"seq":174569,"id":"CVE-2026-56746","ts":1789334771368,"field":"cvss","old":"6.5","new":"7.5"},{"seq":174568,"id":"CVE-2026-56746","ts":1789334771368,"field":"severity","old":"medium","new":"high"},{"seq":173364,"id":"CVE-2026-56746","ts":1789333507259,"field":"cvss","old":"7.5","new":"6.5"},{"seq":173363,"id":"CVE-2026-56746","ts":1789333507259,"field":"severity","old":"high","new":"medium"},{"seq":172178,"id":"CVE-2026-56746","ts":1789331017810,"field":"cvss","old":"6.5","new":"7.5"},{"seq":172177,"id":"CVE-2026-56746","ts":1789331017810,"field":"severity","old":"medium","new":"high"},{"seq":170992,"id":"CVE-2026-56746","ts":1789328614371,"field":"cvss","old":"7.5","new":"6.5"},{"seq":170991,"id":"CVE-2026-56746","ts":1789328614371,"field":"severity","old":"high","new":"medium"},{"seq":169787,"id":"CVE-2026-56746","ts":1789327050750,"field":"cvss","old":"6.5","new":"7.5"},{"seq":169786,"id":"CVE-2026-56746","ts":1789327050750,"field":"severity","old":"medium","new":"high"}]}