---
id: CVE-2026-93567
title: A flaw was found in Netty's HTTP/2 codec
summary: >-
  A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT
  requests to HTTP/2, the component incorrectly uses the Host header instead of
  the CONNECT authority-form request-target for the tunnel authority. A remote
  attacker …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-20
vendor: Red Hat
product: netty-codec-http2
affected:
  - netty-codec-http2
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
published: '2026-09-18'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:16:58.203'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93567'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:69440'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69470'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70257'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-93567'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2536955'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93567.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-93567'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93567'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T19:48:36.822411Z'
epss: 0.00555
epssPercentile: 0.45162
ingestedAt: '2026-09-18T14:43:13.068Z'
---

## Overview

A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit this by supplying a different Host header, leading to a malformed HTTP/2 CONNECT request. This can bypass security controls such as tunnel allow-lists or egress policies, resulting in integrity loss.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat Data Grid 8, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, Red Hat build of Apache Camel 4 for Quarkus 3, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93567.json)
