CVE-2026-93562
Awaiting Analysis
Awaiting Analysis - Queue
BaseFortify
Vulnerability report for CVE-2026-93562, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-18
Last updated on: 2026-10-09
Assigner: redhat-SADP
Description
Description
A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP requests, potentially bypassing security controls or accessing unauthorized resources.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netty | netty | From 4.2.0_final (inc) to 4.2.17_final (inc) |
| netty | netty | to 4.1.137_final (inc) |
| red_hat | quarkus | 3.27.5_sp2 |
| red_hat | quarkus | 3.33.3_sp2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1035 |