---
id: CVE-2023-0833
title: >-
  A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp
  component with an information disclosure flaw via an exception triggered by a
  header containing an illegal value
summary: >-
  A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp
  component with an information disclosure flaw via an exception triggered by a
  header containing an illegal value. This issue could allow an authenticated
  atta…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-209
  - CWE-209
vendor: squareup
product: okhttp
affected:
  - okhttp < 4.9.2
  - a-mq_streams < 2.2.1
  - 'a-mq_streams >= 2.3.0, < 2.4.0'
patched:
  - okhttp 4.9.2
  - a-mq_streams 2.4.0
published: '2023-09-27'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-0833'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2023:1241'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:3223'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-0833'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2169845'
    label: secalert@redhat.com
  - url: 'https://github.com/square/okhttp/issues/6738'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:1241'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:3223'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-0833'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2169845'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/square/okhttp/issues/6738'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00436
epssPercentile: 0.37383
ingestedAt: '2026-06-29T13:24:33.907Z'
---

## Overview

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.

## Affected

- `okhttp < 4.9.2`
- `a-mq_streams < 2.2.1`
- `a-mq_streams >= 2.3.0, < 2.4.0`

## Remediation

Upgrade past the affected range:

- `okhttp 4.9.2`
- `a-mq_streams 2.4.0`
