Impact
The vulnerability arises from the Netty HTTP/2 codec translating an HTTP/1 CONNECT request in authority form into a malformed HTTP/2 CONNECT request that places the host value into the :authority header without proper validation. This improper input validation (CWE‑20) allows an attacker who can send a CONNECT request to the server to dictate the :authority header value, effectively directing the server to establish connections to arbitrary hosts. The impact can include unauthorized network reachability, bypassing filtering or firewall rules, and potentially enabling downstream data exfiltration or lateral movement.
Affected Systems
Multiple Red Hat products are affected, including Red Hat AMQ Broker 7, Red Hat build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, and Red Hat build of Quarkus. No specific version ranges are supplied in the advisory; customers should refer to the Red Hat security page for the exact patch versions.
Risk and Exploitability
The CVSS score of 7.5 classifies this flaw as a high‑severity vulnerability. Because the flaw is tied to input handling of CONNECT requests, an attacker only needs to be able to send HTTP traffic to the affected service, which is commonly exposed. The EPSS score is < 1%. The absence of a KEV listing suggests no known widespread exploitation yet. Nevertheless, a crafted CONNECT request could redirect the server to an attacker‑controlled host, potentially facilitating unauthorized connections or data leakage.
OpenCVE Enrichment