CVE-2026-93579
Awaiting Analysis
Awaiting Analysis - Queue
BaseFortify
Vulnerability report for CVE-2026-93579, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-18
Last updated on: 2026-09-29
Assigner: redhat-SADP
Description
Description
A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cross an HTTP/2 to HTTP/1.1 translation boundary, they can be exploited for request smuggling, header injection, or response splitting. This could lead to unauthorized access, data manipulation, or other security bypasses.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netty | netty_codec_http2 | 4.1.137_final |
| netty | netty_codec_http2 | From 4.2.0_final (inc) to 4.2.17_final (inc) |
| red_hat | quarkus | 3.27.5_sp2 |
| red_hat | quarkus | 3.33.3_sp2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1035 |