Impact
The vulnerability is a host header mis‑translation in the Netty HTTP/2 codec. An attacker can send an HTTP/1 request that uses an absolute‑form URL with a Host header that does not match the request target. Netty then translates the request into HTTP/2 and overrides the requested authority with the supplied Host, causing the server to forward the request to the wrong origin or resource. This can allow unauthorized access to internal services or redirect traffic to malicious hosts.
Affected Systems
Red Hat application stacks that embed Netty include Red Hat AMQ Broker 7, Build of Keycloak, Data Grid 8, Fuse 7, JBoss Enterprise Application Platform 7 and 8, Single Sign‑On 7, Build of Apache Camel 4 for Quarkus 3, Build of Apache Camel for Spring Boot 4, Apicurio Registry 3, Debezium 3, and Quarkus 3. Affected versions are not listed in the advisory; any installation that uses Netty and serves HTTP/2 is potentially impacted.
Risk and Exploitability
The CVSS score of 8.2 classifies this as high severity. EPSS score of 0.00372 indicates a very low but non-zero exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. However it can be exploited by an attacker with network access to send a crafted HTTP/1 request to the vulnerable endpoint. The exploitation chain requires merely sending the request; no authentication is necessary or necessary pre‑conditions beyond being able to reach the application. Attackers may therefore leverage this flaw for request smuggling or to bypass access controls.
OpenCVE Enrichment