Description
A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this field, can embed CR/LF characters to inject arbitrary SMTP commands. This can lead to SMTP command smuggling, allowing for unauthorized email relay or spoofing of sender/recipient addresses. While the impact is significant, the real-world exploitability is considered lower as applications typically do not place user-controlled data in the command-name field.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Improper Input Validation
Action: Immediate Patch
AI Analysis

Impact

Netty's SMTP codec does not properly validate Carriage Return and Line Feed characters in the SMTP command-name field. Because command-name can contain untrusted user input, an attacker can embed CR/LF pairs to inject additional SMTP commands, a technique known as SMTP command smuggling. This can be used to relay mail through the affected server or to spoof sender or recipient email addresses, effectively enabling unauthorized email transmission. The flaw is classified as CWE-93 and, while it does not directly provide code execution, it allows misuse of the SMTP interface to conduct spam or phishing campaigns.

Affected Systems

Affected products include Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign-On 7, and the Red Hat build of Apache Camel for Spring Boot version 4. All supported releases of these products that embed the vulnerable netty- codec-smtp component are potentially impacted, as the CVE data does not list specific version restrictions.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score is less than 1%, showing that exploitation is currently considered unlikely. This vulnerability is not listed in the CISA KEV catalog. The vulnerability resides in a network-exposed SMTP codec, so the most likely attack vector is remote, involving crafted SMTP connections that deliver malicious command-name fields to trigger the smuggling behavior.

Generated by OpenCVE AI on September 19, 2026 at 16:22 UTC.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-5vh9-c45f-rf7p for fixed versions and remediation guidance.


OpenCVE Recommended Actions

  • Update netty- codec-smtp to the latest patched release that includes the complete fix for this issue.
  • Follow the remediation guidance in the Netty GitHub advisory at https://github.com/netty/netty/security/advisories/GHSA-5vh9-c45f-rf7p, which includes any additional configuration or patch steps required.
  • Limit exposure by implementing network segmentation or firewall rules that restrict untrusted SMTP traffic to services running the affected components.

Generated by OpenCVE AI on September 19, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3
Vendors & Products Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419) A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this field, can embed CR/LF characters to inject arbitrary SMTP commands. This can lead to SMTP command smuggling, allowing for unauthorized email relay or spoofing of sender/recipient addresses. While the impact is significant, the real-world exploitability is considered lower as applications typically do not place user-controlled data in the command-name field.
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
Title Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419)
First Time appeared Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
Weaknesses CWE-93
CPEs cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Io.netty Netty-codec-http
Redhat Build Of Apache Camel For Spring Boot Camel Spring Boot Jboss Enterprise Application Platform Jboss Fuse Quay 3 Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T08:29:13.508Z

Reserved: 2026-09-18T10:33:56.511Z

Link: CVE-2026-93576

cve-icon Vulnrichment

Updated: 2026-09-18T14:58:47.576Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:21.167

Modified: 2026-09-25T09:17:07.767

Link: CVE-2026-93576

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:53:44Z

Links: CVE-2026-93576 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:26Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')