CVE Intelligence
Skip to main content
MEDIUM

CVE-2026-93579

CVE-2026-93579 — Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough)

A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cross an HTTP/2 to HTTP/1.1 translation boundary, they can be exploited for request smuggling, header injection, or response splitting. This could lead to unauthorized access, data manipulation, or other security bypasses.

Published Updated Sources: cvelistV5, redhat

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

Not scored

FIRST has not published a score

Affects

redhat

12 products listed

CVSS base

6.5

MEDIUM

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (1)

Products (12)

red hat amq broker 7red hat build of apache camel 4 for quarkus 3red hat build of apache camel for spring boot 4red hat build of apicurio registry 3red hat build of debezium 3red hat build of keycloakred hat build of quarkusred hat data grid 8red hat fuse 7red hat jboss enterprise application platform 7red hat jboss enterprise application platform 8red hat single sign on 7

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
6.5CVSS 3.1MEDIUMcvelistV5

Weakness & attack patterns

  • CWE-1035

Detection

Read off the CVSS vector and the weakness class. Starting points, not rules we have tested.

  • Search application, proxy, and WAF logs for requests touching /2, /1.1.

References

2 on the record

Elsewhere on this site

  • redhatevery CVE for this vendor
  • CWE-1035other pages naming this weakness

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.