Description
A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to increased CPU usage and memory consumption, ultimately resulting in a Denial of Service (DoS).
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (CPU and memory exhaustion)
Action: Monitor
AI Analysis

Impact

A flaw in Netty’s HTTP/2 HpackEncoder allows a remote attacker to send a SETTINGS frame with an oversized MAX_HEADER_TABLE_SIZE. This causes the encoder to store an enormous number of unique headers, which in turn drives CPU usage and swells memory consumption until the application becomes unresponsive. The result is a denial of service that can be triggered purely by sending HTTP/2 traffic; no code execution or privilege escalation is required. The vulnerability exemplifies a classic resource exhaustion weakness (CWE‑1035).

Affected Systems

The issue surfaces in Netty components that are embedded within a variety of Red Hat products. Affected offerings include Red Hat AMQ Broker 7, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, and Red Hat build of Debezium 3. The data does not provide specific fixed or affected versions, so any installation that incorporates this version of Netty is potentially vulnerable.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. EPSS is listed as < 1 %, and the vulnerability is not in the CISA KEV catalog. Exploitation requires only an HTTP/2 connection from a remote client and the ability to send a SETTINGS frame with an excessively large MAX_HEADER_TABLE_SIZE. No authentication or privileged access is necessary; the attack leverages resource exhaustion rather than code execution.

Generated by OpenCVE AI on September 19, 2026 at 19:38 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Configure your HTTP/2 server or application layer to limit the MAX_HEADER_TABLE_SIZE (for example, to 65,536 bytes) so that oversized SETTINGS frames are rejected or truncated.
  • Deploy a network‑level proxy, load balancer, or firewall rule that inspects HTTP/2 frames and blocks SETTINGS frames with a MAX_HEADER_TABLE_SIZE exceeding the allowed threshold.
  • Monitor CPU and memory usage of Netty‑based services and configure alerts or automated restarts when utilization surpasses defined thresholds.

Generated by OpenCVE AI on September 19, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
References

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Io.netty
Io.netty netty-codec-http2
Redhat amq Broker 7
Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot
Redhat build Of Apicurio Registry
Redhat build Of Debezium 3
Redhat build Of Keycloak
Redhat build Of Quarkus
Redhat data Grid 8
Redhat quay 3
Redhat single Sign-on
Vendors & Products Io.netty
Io.netty netty-codec-http2
Redhat amq Broker 7
Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot
Redhat build Of Apicurio Registry
Redhat build Of Debezium 3
Redhat build Of Keycloak
Redhat build Of Quarkus
Redhat data Grid 8
Redhat quay 3
Redhat single Sign-on

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:quarkus:3
Vendors & Products Redhat quarkus
References

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to increased CPU usage and memory consumption, ultimately resulting in a Denial of Service (DoS).
Title Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size
First Time appeared Redhat
Redhat amq Broker
Redhat apicurio Registry
Redhat build Keycloak
Redhat camel Quarkus
Redhat camel Spring Boot
Redhat debezium
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat quarkus
Redhat red Hat Single Sign On
Weaknesses CWE-1035
CPEs cpe:/a:redhat:amq_broker:7
cpe:/a:redhat:apicurio_registry:3
cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:camel_quarkus:3
cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:debezium:3
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:quarkus:3
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat amq Broker
Redhat apicurio Registry
Redhat build Keycloak
Redhat camel Quarkus
Redhat camel Spring Boot
Redhat debezium
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat quarkus
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Io.netty Netty-codec-http2
Redhat Amq Broker Amq Broker 7 Apicurio Registry Build Keycloak Build Of Apache Camel For Quarkus Build Of Apache Camel For Spring Boot Build Of Apicurio Registry Build Of Debezium 3 Build Of Keycloak Build Of Quarkus Camel Quarkus Camel Spring Boot Data Grid 8 Debezium Jboss Data Grid Jboss Enterprise Application Platform Jboss Fuse Quay 3 Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-29T20:55:23.375Z

Reserved: 2026-09-18T07:15:03.252Z

Link: CVE-2026-93492

cve-icon Vulnrichment

Updated: 2026-09-18T14:40:20.723Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T13:18:38.877

Modified: 2026-09-29T21:19:38.990

Link: CVE-2026-93492

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T00:41:18Z

Links: CVE-2026-93492 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:43Z

Weaknesses