A flaw was found in Netty netty-codec-smtp. (CVE-2026-93576)
A vulnerability in Netty's netty-codec-smtp component allows improper validation of CR and LF characters in the SMTP command-name field. This flaw can enable remote attackers to inject arbitrary SMTP commands if untrusted input is routed into this field, potentially leading to SMTP command smuggling, unauthorized email relay, or spoofing of sender/recipient addresses. However, exploitation is limited because applications rarely place user-controlled data in the command-name field.
AI Analysis
Technical Summary
CVE-2026-93576 is a CRLF injection vulnerability in Netty's netty-codec-smtp component where the SMTP command-name field does not properly validate Carriage Return (CR) and Line Feed (LF) characters. This allows a remote attacker to inject arbitrary SMTP commands if untrusted input is routed into this field, resulting in SMTP command smuggling. The vulnerability can lead to unauthorized email relay or spoofing of sender or recipient addresses. Despite the significant impact, real-world exploitability is considered low due to the uncommon practice of routing user-controlled data into the SMTP command-name field. The vulnerability affects multiple specific versions of Netty as listed, and remediation guidance including fixed versions is available from the vendor.
Potential Impact
The vulnerability allows attackers to inject arbitrary SMTP commands remotely, which can lead to unauthorized email relay or spoofing of sender and recipient addresses. This compromises the integrity of SMTP communications. However, the confidentiality and availability impacts are not affected. The real-world risk is reduced because typical applications do not route untrusted input into the SMTP command-name field, limiting exploitability.
Mitigation Recommendations
Fixed versions and remediation guidance are available from the vendor at https://github.com/netty/netty/security/advisories/GHSA-5vh9-c45f-rf7p. Users should upgrade to these fixed versions to address the vulnerability. Since the vulnerability requires routing untrusted input into the SMTP command-name field, reviewing application design to avoid this practice can also mitigate risk. No vendor advisory states that no action is required or that the issue is already mitigated. Patch status is confirmed as fixed in later versions per the vendor advisory.
A flaw was found in Netty netty-codec-smtp. (CVE-2026-93576)
Description
A vulnerability in Netty's netty-codec-smtp component allows improper validation of CR and LF characters in the SMTP command-name field. This flaw can enable remote attackers to inject arbitrary SMTP commands if untrusted input is routed into this field, potentially leading to SMTP command smuggling, unauthorized email relay, or spoofing of sender/recipient addresses. However, exploitation is limited because applications rarely place user-controlled data in the command-name field.
CVSS v3.1
Score 7.5high
Affected software
pkg:deb/ubuntu/netty?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/netty?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/netty?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/netty?arch=source&distro=esm-apps/resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93576 is a CRLF injection vulnerability in Netty's netty-codec-smtp component where the SMTP command-name field does not properly validate Carriage Return (CR) and Line Feed (LF) characters. This allows a remote attacker to inject arbitrary SMTP commands if untrusted input is routed into this field, resulting in SMTP command smuggling. The vulnerability can lead to unauthorized email relay or spoofing of sender or recipient addresses. Despite the significant impact, real-world exploitability is considered low due to the uncommon practice of routing user-controlled data into the SMTP command-name field. The vulnerability affects multiple specific versions of Netty as listed, and remediation guidance including fixed versions is available from the vendor.
Potential Impact
The vulnerability allows attackers to inject arbitrary SMTP commands remotely, which can lead to unauthorized email relay or spoofing of sender and recipient addresses. This compromises the integrity of SMTP communications. However, the confidentiality and availability impacts are not affected. The real-world risk is reduced because typical applications do not route untrusted input into the SMTP command-name field, limiting exploitability.
Mitigation Recommendations
Fixed versions and remediation guidance are available from the vendor at https://github.com/netty/netty/security/advisories/GHSA-5vh9-c45f-rf7p. Users should upgrade to these fixed versions to address the vulnerability. Since the vulnerability requires routing untrusted input into the SMTP command-name field, reviewing application design to avoid this practice can also mitigate risk. No vendor advisory states that no action is required or that the issue is already mitigated. Patch status is confirmed as fixed in later versions per the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-93576
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:Pro:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be2df7a7c54106eeec15
Added to database: 09/24/2026, 06:07:41 UTC
Last enriched: 09/24/2026, 06:25:26 UTC
Last updated: 09/25/2026, 03:47:33 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.