CVE-2026-93567
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Summary
A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit this by supplying a different Host header, leading to a malformed HTTP/2 CONNECT request. This can bypass security controls such as tunnel allow-lists or egress policies, resulting in integrity loss.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-20: Improper Input Validation
Workarounds
See https://github.com/netty/netty/security/advisories/GHSA-45h4-vhwh-fmhg for fixed versions and remediation guidance.
References
- https://access.redhat.com/security/cve/CVE-2026-93567
- https://bugzilla.redhat.com/show_bug.cgi?id=2536955
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.