---
id: CVE-2026-93569
title: A flaw was found in Netty
summary: >-
  A flaw was found in Netty. A remote unauthenticated attacker can exploit a
  vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1
  request includes both an absolute-form request-target and a conflicting Host
  header, …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-444
vendor: Red Hat
product: netty-codec-http2
affected:
  - netty-codec-http2
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
published: '2026-09-18'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:16:58.477'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93569'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:69440'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69470'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70257'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-93569'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2536962'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93569.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-93569'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93569'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-22T14:36:45.463553Z'
epss: 0.00518
epssPercentile: 0.43036
ingestedAt: '2026-09-18T14:43:13.059Z'
---

## Overview

A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat Data Grid 8, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, Red Hat build of Apache Camel 4 for Quarkus 3, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93569.json)
