Impact
The Netty HTTP/2 and HTTP/3 library incorrectly treats Extended CONNECT requests as standard CONNECT requests. Extended CONNECT is designed to add extra metadata for tunneling. Based on the description, it is inferred that when this downgrade occurs the server may accept or reject unexpected connections. This flaw is a CWE‑20, an improper input validation bug, and allows an attacker to send specially crafted HTTP/2 or HTTP/3 frames that bypass application logic expecting the full extended handshake. Based on the description, it is inferred that the result could be service disruption, denial of service, or unauthorized connection establishment if the application does not perform adequate validation.
Affected Systems
Red Hat AMQ Broker 7, Red Hat build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, and Red Hat build of Quarkus 3. Specific version information is not disclosed.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high‑severity vulnerability. The EPSS score of < 1% signifies a very low but non‑zero exploitation probability, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that no currently known widespread exploitation has occurred. Attackers would need network access to a service using Netty that accepts HTTP/2 or HTTP/3 traffic and the ability to craft an Extended CONNECT frame; otherwise the vulnerability is not exploitable. The attack surface is limited to applications that rely on standard CONNECT semantics. An automated exploit could trigger configuration errors or connectivity issues that could lead to service disruption or unauthorized state changes.
OpenCVE Enrichment