A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. (CVE-2026-93568)
A vulnerability in Netty allows remote attackers to bypass security policies by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty incorrectly processes these requests as HTTP/1.1 CONNECT requests, causing loss of critical protocol and path information. This flaw can lead to authorization bypasses in applications relying on Netty for HTTP/2 or HTTP/3 communication, resulting in integrity loss. The vulnerability has a CVSS score of 7.5 (medium severity).
AI Analysis
Technical Summary
Netty's HTTP-object conversion path incorrectly downgrades HTTP/2 and HTTP/3 Extended CONNECT requests to standard HTTP/1.1 CONNECT requests. This misinterpretation causes loss of critical protocol and path information, enabling attackers to bypass security policies such as routing or authorization logic in applications that use Netty for HTTP/2 or HTTP/3 communication. The flaw impacts integrity by allowing unauthorized actions. The vulnerability is identified as CVE-2026-93568 with a CVSS v3.1 score of 7.5. Red Hat advisory confirms this issue affects multiple Netty versions and provides links to fixed versions and remediation guidance.
Potential Impact
The vulnerability allows remote attackers to bypass security policies, including routing and authorization, due to improper handling of Extended CONNECT requests. This leads to integrity loss in affected applications. There is no direct confidentiality or availability impact reported. The flaw can cause applications acting as gateways, proxies, or servers using Netty to improperly enforce security policies.
Mitigation Recommendations
A fix is available. Refer to the official Red Hat advisory and Netty's GitHub security advisories (https://github.com/netty/netty/security/advisories/GHSA-w6j8-x45j-w75f) for fixed versions and remediation guidance. Users should upgrade to patched versions of Netty to address this vulnerability. No vendor advisory states that no action is required or that the issue is already mitigated without patching.
A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. (CVE-2026-93568)
Description
A vulnerability in Netty allows remote attackers to bypass security policies by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty incorrectly processes these requests as HTTP/1.1 CONNECT requests, causing loss of critical protocol and path information. This flaw can lead to authorization bypasses in applications relying on Netty for HTTP/2 or HTTP/3 communication, resulting in integrity loss. The vulnerability has a CVSS score of 7.5 (medium severity).
CVSS v3.1
Score 7.5high
Affected software
pkg:deb/ubuntu/netty?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/netty?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/netty?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/netty?arch=source&distro=esm-apps/resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Netty's HTTP-object conversion path incorrectly downgrades HTTP/2 and HTTP/3 Extended CONNECT requests to standard HTTP/1.1 CONNECT requests. This misinterpretation causes loss of critical protocol and path information, enabling attackers to bypass security policies such as routing or authorization logic in applications that use Netty for HTTP/2 or HTTP/3 communication. The flaw impacts integrity by allowing unauthorized actions. The vulnerability is identified as CVE-2026-93568 with a CVSS v3.1 score of 7.5. Red Hat advisory confirms this issue affects multiple Netty versions and provides links to fixed versions and remediation guidance.
Potential Impact
The vulnerability allows remote attackers to bypass security policies, including routing and authorization, due to improper handling of Extended CONNECT requests. This leads to integrity loss in affected applications. There is no direct confidentiality or availability impact reported. The flaw can cause applications acting as gateways, proxies, or servers using Netty to improperly enforce security policies.
Mitigation Recommendations
A fix is available. Refer to the official Red Hat advisory and Netty's GitHub security advisories (https://github.com/netty/netty/security/advisories/GHSA-w6j8-x45j-w75f) for fixed versions and remediation guidance. Users should upgrade to patched versions of Netty to address this vulnerability. No vendor advisory states that no action is required or that the issue is already mitigated without patching.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-93568
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:Pro:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be2ef7a7c54106eeec1f
Added to database: 09/24/2026, 06:07:42 UTC
Last enriched: 09/24/2026, 06:28:19 UTC
Last updated: 09/25/2026, 03:47:33 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.