Description
A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.
Published: 2026-09-18
Score: 8.2 High
EPSS: 1.4% Low
KEV: No
Impact: Unauthorized request forwarding via :authority header manipulation
Action: Patch Now
AI Analysis

Impact

The vulnerability is a host header mis‑translation in the Netty HTTP/2 codec. An attacker can send an HTTP/1 request that uses an absolute‑form URL with a Host header that does not match the request target. Netty then translates the request into HTTP/2 and overrides the requested authority with the supplied Host, causing the server to forward the request to the wrong origin or resource. This can allow unauthorized access to internal services or redirect traffic to malicious hosts.

Affected Systems

Red Hat application stacks that embed Netty include Red Hat AMQ Broker 7, Build of Keycloak, Data Grid 8, Fuse 7, JBoss Enterprise Application Platform 7 and 8, Single Sign‑On 7, Build of Apache Camel 4 for Quarkus 3, Build of Apache Camel for Spring Boot 4, Apicurio Registry 3, Debezium 3, and Quarkus 3. Affected versions are not listed in the advisory; any installation that uses Netty and serves HTTP/2 is potentially impacted.

Risk and Exploitability

The CVSS score of 8.2 classifies this as high severity. EPSS score of 0.00372 indicates a very low but non-zero exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. However it can be exploited by an attacker with network access to send a crafted HTTP/1 request to the vulnerable endpoint. The exploitation chain requires merely sending the request; no authentication is necessary or necessary pre‑conditions beyond being able to reach the application. Attackers may therefore leverage this flaw for request smuggling or to bypass access controls.

Generated by OpenCVE AI on September 19, 2026 at 17:26 UTC.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m for fixed versions and remediation guidance.


OpenCVE Recommended Actions

  • Upgrade the affected Red Hat products to a version that includes the fixed Netty release as documented by Red Hat
  • Apply the workaround by upgrading to a patched Netty version or configuring your Netty runtime to use a fixed release, following guidance from the GitHub security advisory at https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m
  • If an immediate patch is not feasible, restrict or block HTTP/1 absolute-form requests with mismatched Host headers at the network or proxy layer, as recommended in the advisory

Generated by OpenCVE AI on September 19, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000


Mon, 21 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:quarkus:3
Vendors & Products Redhat quarkus
References

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot
Redhat build Of Apicurio Registry
Redhat build Of Debezium 3
Redhat build Of Keycloak
Redhat build Of Quarkus
Redhat data Grid 8
Redhat quay 3
Vendors & Products Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot
Redhat build Of Apicurio Registry
Redhat build Of Debezium 3
Redhat build Of Keycloak
Redhat build Of Quarkus
Redhat data Grid 8
Redhat quay 3

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority
Title Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authority, overriding the request-target authority
First Time appeared Redhat
Redhat amq Broker
Redhat apicurio Registry
Redhat build Keycloak
Redhat camel Quarkus
Redhat camel Spring Boot
Redhat debezium
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat quarkus
Redhat red Hat Single Sign On
Weaknesses CWE-444
CPEs cpe:/a:redhat:amq_broker:7
cpe:/a:redhat:apicurio_registry:3
cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:camel_quarkus:3
cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:debezium:3
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:quarkus:3
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat amq Broker
Redhat apicurio Registry
Redhat build Keycloak
Redhat camel Quarkus
Redhat camel Spring Boot
Redhat debezium
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat quarkus
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Io.netty Netty-codec-http
Redhat Amq Broker Apicurio Registry Build Keycloak Build Of Apache Camel For Quarkus Build Of Apache Camel For Spring Boot Build Of Apicurio Registry Build Of Debezium 3 Build Of Keycloak Build Of Quarkus Camel Quarkus Camel Spring Boot Data Grid 8 Debezium Jboss Data Grid Jboss Enterprise Application Platform Jboss Fuse Quay 3 Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T18:55:52.098Z

Reserved: 2026-09-18T10:05:12.467Z

Link: CVE-2026-93569

cve-icon Vulnrichment

Updated: 2026-09-22T14:37:04.969Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:20.743

Modified: 2026-09-22T19:16:58.477

Link: CVE-2026-93569

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:51:06Z

Links: CVE-2026-93569 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:28Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')