Impact
A flaw in Netty’s HTTP/2 stack allows a remote attacker to inject prohibited characters such as NUL, line feed, or carriage return into header field values because the library does not perform validation by default. When these values cross the HTTP/2 to HTTP/1.1 translation boundary, they can be leveraged for request smuggling, header injection, or response splitting. The consequence is that an attacker may obtain unauthorized access, manipulate data, or otherwise bypass security controls.
Affected Systems
The vulnerability impacts several Red Hat‑based distributions that embed Netty, including Red Hat AMQ Broker 7, the Red Hat build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, the Red Hat build of Apache Camel 4 for Quarkus 3, the Red Hat build of Apache Camel for Spring Boot 4, the Red Hat build of Apicurio Registry 3, the Red Hat build of Debezium 3, and the Red Hat build of Quarkus. No specific affected version ranges are provided, so the vulnerability may exist in any release that incorporates an unpatched version of Netty.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it remotely over a network that accepts HTTP/2 traffic by sending crafted header values containing NUL, CR, or LF characters. No local privilege escalation or authentication is required, but successful exploitation can lead to unauthorized data access or manipulation.
OpenCVE Enrichment