---
id: CVE-2026-93579
title: A flaw was found in Netty's HTTP/2 stack
summary: >-
  A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote
  attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage
  Return, into HTTP/2 header field values due to insufficient validation. When
  thes…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-1035
vendor: Red Hat
product: netty-codec-http2
affected:
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2 (all versions)
  - netty-codec-http2
  - netty-codec-http2
  - netty-codec-http2
  - netty-codec-http2
  - netty-codec-http2 (all versions)
  - netty-codec-http2
published: '2026-09-18'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T21:17:18.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93579'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:69470'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-93579'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2536970'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93579.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-93579'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93579'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T19:48:39.163858Z'
epss: 0.00231
epssPercentile: 0.14185
ingestedAt: '2026-09-18T16:45:41.406Z'
---

## Overview

A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cross an HTTP/2 to HTTP/1.1 translation boundary, they can be exploited for request smuggling, header injection, or response splitting. This could lead to unauthorized access, data manipulation, or other security bypasses.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat AMQ Broker 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, … · no fix planned: Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93579.json)
