CVE-2026-93566: CWE-1035 in Red Hat Red Hat AMQ Broker 7
A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.
AI Analysis
Technical Summary
The vulnerability exists in the Netty HTTP decoder used by Red Hat AMQ Broker 7, specifically in the method io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions. The method only applies strict validation of chunk size lines if a chunk extension (indicated by a semicolon) is present. If no semicolon is found, the validation is skipped, allowing chunk size lines with embedded bare carriage return characters (e.g., '0\rX') to be accepted. This behavior violates RFC 9112 requirements for chunk-size syntax and enables HTTP request smuggling attacks. A proof-of-concept demonstrates sending a chunked HTTP request with a malformed chunk size line that is accepted by the decoder.
Potential Impact
An attacker can exploit this vulnerability to perform HTTP request smuggling against Red Hat AMQ Broker 7 instances using the affected Netty version. This may allow bypassing security controls, request splitting, or other HTTP-level attacks that rely on manipulating chunked transfer encoding parsing. The CVSS score of 6.5 indicates a medium impact with low complexity and no privileges required.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-93566 for current remediation guidance. Until an official fix is available, consider applying any recommended temporary mitigations from the vendor advisory. Do not assume the vulnerability is mitigated without vendor confirmation.
CVE-2026-93566: CWE-1035 in Red Hat Red Hat AMQ Broker 7
Description
A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.
CVSS v3.1
Score 6.5medium
Affected software
Red Hat
Red Hat AMQ Broker 7
Red Hat
Red Hat AMQ Clients
Red Hat
Red Hat build of Apache Camel 4 for Quarkus 3
Red Hat
Red Hat build of Apache Camel for Spring Boot 4
Red Hat
Red Hat build of Apicurio Registry 3
Red Hat
Red Hat build of Debezium 3
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat build of Quarkus
Red Hat
Red Hat Data Grid 8
Red Hat
Red Hat Fuse 7
Red Hat
Red Hat JBoss Enterprise Application Platform 7
Red Hat
Red Hat JBoss Enterprise Application Platform 8
Red Hat
Red Hat Single Sign-On 7
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the Netty HTTP decoder used by Red Hat AMQ Broker 7, specifically in the method io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions. The method only applies strict validation of chunk size lines if a chunk extension (indicated by a semicolon) is present. If no semicolon is found, the validation is skipped, allowing chunk size lines with embedded bare carriage return characters (e.g., '0\rX') to be accepted. This behavior violates RFC 9112 requirements for chunk-size syntax and enables HTTP request smuggling attacks. A proof-of-concept demonstrates sending a chunked HTTP request with a malformed chunk size line that is accepted by the decoder.
Potential Impact
An attacker can exploit this vulnerability to perform HTTP request smuggling against Red Hat AMQ Broker 7 instances using the affected Netty version. This may allow bypassing security controls, request splitting, or other HTTP-level attacks that rely on manipulating chunked transfer encoding parsing. The CVSS score of 6.5 indicates a medium impact with low complexity and no privileges required.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-93566 for current remediation guidance. Until an official fix is available, consider applying any recommended temporary mitigations from the vendor advisory. Do not assume the vulnerability is mitigated without vendor confirmation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-18T10:00:52.431Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-93566","vendor":"Red Hat"}]
Threat ID: 6aad4b7355bf5e2cf51f5ed2
Added to database: 09/18/2026, 14:32:19 UTC
Last enriched: 09/18/2026, 14:47:13 UTC
Last updated: 09/19/2026, 00:02:58 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.