CVE-2026-93569: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in Red Hat Red Hat AMQ Broker 7
A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.
AI Analysis
Technical Summary
CVE-2026-93569 describes an HTTP request smuggling vulnerability in Red Hat AMQ Broker 7 where an HTTP/1 absolute-form Host mismatch is incorrectly translated to the HTTP/2 :authority header, overriding the intended request-target authority. This inconsistent interpretation can be exploited to bypass security controls, poison web caches, or leak client credentials. The vulnerability is tracked under CWE-444 (Inconsistent Interpretation of HTTP Requests). Red Hat's advisory points to a related fix in the Netty project (netty-codec-http2) and provides guidance via the Netty security advisory. However, Red Hat does not explicitly confirm fixed versions or patch availability for AMQ Broker 7 in the advisory. The CVSS 3.1 base score is 8.2 (high severity), reflecting network attack vector, low complexity, no privileges required, no user interaction, unchanged scope, low confidentiality impact, high integrity impact, and no availability impact.
Potential Impact
The vulnerability allows an attacker to craft HTTP messages that exploit inconsistent HTTP request parsing, potentially enabling web cache poisoning, firewall bypass, unauthorized access to web applications, and leakage of client credentials. The integrity of the affected system can be compromised, but availability is not impacted. Confidentiality impact is low. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat's advisory references the Netty project's security advisory (https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m) for fixed versions and remediation guidance. Users of Red Hat AMQ Broker 7 should consult this advisory and Red Hat's official security page (https://access.redhat.com/security/cve/CVE-2026-93569) for updates on patch availability. Since no explicit patch or fixed version is stated for AMQ Broker 7, patch status is not yet confirmed. Users should monitor vendor advisories for official fixes and apply them when available. No vendor advisory states that no action is required or that the issue is already mitigated.
CVE-2026-93569: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in Red Hat Red Hat AMQ Broker 7
Description
A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host header for the HTTP/2 :authority field, discarding the original request-target authority. This inconsistency can allow an attacker to bypass security controls in Netty-based proxies or gateways, potentially leading to unauthorized access, cache poisoning, or misrouting of requests.
CVSS v3.1
Score 8.2high
Affected software
Red Hat
Red Hat AMQ Broker 7
Red Hat
Red Hat build of Apache Camel 4 for Quarkus 3
Red Hat
Red Hat build of Apache Camel for Spring Boot 4
Red Hat
Red Hat build of Apicurio Registry 3
Red Hat
Red Hat build of Debezium 3
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat build of Quarkus
Red Hat
Red Hat Data Grid 8
Red Hat
Red Hat Fuse 7
Red Hat
Red Hat JBoss Enterprise Application Platform 7
Red Hat
Red Hat JBoss Enterprise Application Platform 8
Red Hat
Red Hat Single Sign-On 7
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93569 describes an HTTP request smuggling vulnerability in Red Hat AMQ Broker 7 where an HTTP/1 absolute-form Host mismatch is incorrectly translated to the HTTP/2 :authority header, overriding the intended request-target authority. This inconsistent interpretation can be exploited to bypass security controls, poison web caches, or leak client credentials. The vulnerability is tracked under CWE-444 (Inconsistent Interpretation of HTTP Requests). Red Hat's advisory points to a related fix in the Netty project (netty-codec-http2) and provides guidance via the Netty security advisory. However, Red Hat does not explicitly confirm fixed versions or patch availability for AMQ Broker 7 in the advisory. The CVSS 3.1 base score is 8.2 (high severity), reflecting network attack vector, low complexity, no privileges required, no user interaction, unchanged scope, low confidentiality impact, high integrity impact, and no availability impact.
Potential Impact
The vulnerability allows an attacker to craft HTTP messages that exploit inconsistent HTTP request parsing, potentially enabling web cache poisoning, firewall bypass, unauthorized access to web applications, and leakage of client credentials. The integrity of the affected system can be compromised, but availability is not impacted. Confidentiality impact is low. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat's advisory references the Netty project's security advisory (https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m) for fixed versions and remediation guidance. Users of Red Hat AMQ Broker 7 should consult this advisory and Red Hat's official security page (https://access.redhat.com/security/cve/CVE-2026-93569) for updates on patch availability. Since no explicit patch or fixed version is stated for AMQ Broker 7, patch status is not yet confirmed. Users should monitor vendor advisories for official fixes and apply them when available. No vendor advisory states that no action is required or that the issue is already mitigated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-18T10:05:12.467Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-93569","vendor":"Red Hat"}]
Threat ID: 6aad4ef655bf5e2cf5230f7e
Added to database: 09/18/2026, 14:47:18 UTC
Last enriched: 09/18/2026, 15:01:35 UTC
Last updated: 09/19/2026, 01:57:57 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.