CVE-2026-93492
Awaiting Analysis
Awaiting Analysis - Queue
BaseFortify
Vulnerability report for CVE-2026-93492, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-18
Last updated on: 2026-09-29
Assigner: redhat-SADP
Description
Description
A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to increased CPU usage and memory consumption, ultimately resulting in a Denial of Service (DoS).
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netty | netty_codec_http2 | From 4.1.137.Final (inc) to 4.2.17.Final (inc) |
| red_hat | quarkus | 3.27.5.SP2 |
| red_hat | quarkus | 3.33.3.SP2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1035 |