A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. (CVE-2026-93569)
A vulnerability in Netty's HTTP/1 to HTTP/2 conversion process allows a remote unauthenticated attacker to bypass security controls. The flaw occurs when an HTTP/1 request contains both an absolute-form request-target and a conflicting Host header; Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can lead to unauthorized access, cache poisoning, or misrouting of requests in Netty-based proxies or gateways.
AI Analysis
Technical Summary
CVE-2026-93569 describes a security flaw in Netty's handling of HTTP/1 to HTTP/2 conversion. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty prioritizes the Host header for the HTTP/2 :authority field, ignoring the original request-target authority. This inconsistency can be exploited by remote unauthenticated attackers to bypass security policies in Netty-based HTTP/1 to HTTP/2 proxies or gateways. Potential impacts include unauthorized access, cache poisoning, and unintended request routing. The vulnerability has a CVSS v3.1 score of 8.2 (high severity) with network attack vector, low complexity, no privileges required, no user interaction, unchanged scope, low confidentiality impact, high integrity impact, and no availability impact. Red Hat provides advisories and fixed versions linked in their security advisory.
Potential Impact
The vulnerability allows remote unauthenticated attackers to bypass security controls in Netty-based proxies or gateways by exploiting inconsistent interpretation of HTTP/1 Host headers and HTTP/2 :authority fields. This can lead to unauthorized access, cache poisoning attacks, and misrouting of requests, potentially compromising host or tenant security boundaries and integrity of web applications relying on Netty for HTTP/2 translation.
Mitigation Recommendations
Fixed versions and remediation guidance are available as per the Red Hat advisory and Netty's GitHub security advisory (https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m). Users should upgrade to fixed versions of Netty to address this vulnerability. No vendor advisory states that no action is required or that the issue is already mitigated without patching. Patch status is confirmed by the vendor advisory. Users should consult the linked advisories for exact fixed versions and apply updates accordingly.
A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. (CVE-2026-93569)
Description
A vulnerability in Netty's HTTP/1 to HTTP/2 conversion process allows a remote unauthenticated attacker to bypass security controls. The flaw occurs when an HTTP/1 request contains both an absolute-form request-target and a conflicting Host header; Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can lead to unauthorized access, cache poisoning, or misrouting of requests in Netty-based proxies or gateways.
CVSS v3.1
Score 8.2high
Affected software
pkg:deb/ubuntu/netty?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/netty?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/netty?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/netty?arch=source&distro=esm-apps/resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93569 describes a security flaw in Netty's handling of HTTP/1 to HTTP/2 conversion. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty prioritizes the Host header for the HTTP/2 :authority field, ignoring the original request-target authority. This inconsistency can be exploited by remote unauthenticated attackers to bypass security policies in Netty-based HTTP/1 to HTTP/2 proxies or gateways. Potential impacts include unauthorized access, cache poisoning, and unintended request routing. The vulnerability has a CVSS v3.1 score of 8.2 (high severity) with network attack vector, low complexity, no privileges required, no user interaction, unchanged scope, low confidentiality impact, high integrity impact, and no availability impact. Red Hat provides advisories and fixed versions linked in their security advisory.
Potential Impact
The vulnerability allows remote unauthenticated attackers to bypass security controls in Netty-based proxies or gateways by exploiting inconsistent interpretation of HTTP/1 Host headers and HTTP/2 :authority fields. This can lead to unauthorized access, cache poisoning attacks, and misrouting of requests, potentially compromising host or tenant security boundaries and integrity of web applications relying on Netty for HTTP/2 translation.
Mitigation Recommendations
Fixed versions and remediation guidance are available as per the Red Hat advisory and Netty's GitHub security advisory (https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m). Users should upgrade to fixed versions of Netty to address this vulnerability. No vendor advisory states that no action is required or that the issue is already mitigated without patching. Patch status is confirmed by the vendor advisory. Users should consult the linked advisories for exact fixed versions and apply updates accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-93569
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:Pro:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be2ef7a7c54106eeec1e
Added to database: 09/24/2026, 06:07:42 UTC
Last enriched: 09/24/2026, 06:27:59 UTC
Last updated: 09/25/2026, 04:47:34 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.