{"api_version":"1","generated_at":"2026-09-20T16:51:17+00:00","cve":"CVE-2026-93566","urls":{"html":"https://cve.report/CVE-2026-93566","api":"https://cve.report/api/cve/CVE-2026-93566.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93566","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93566"},"summary":{"title":"Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line","description":"A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-09-18 15:17:20","updated_at":"2026-09-18 21:18:47"},"problem_types":["CWE-1035","CWE-1035 CWE-1035"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-93566","name":"https://access.redhat.com/security/cve/CVE-2026-93566","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2536954","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2536954","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93566","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93566","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat AMQ Broker 7","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat AMQ Clients","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat build of Apache Camel 4 for Quarkus 3","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat build of Apache Camel for Spring Boot 4","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat build of Apicurio Registry 3","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat build of Debezium 3","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Build of Keycloak","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat build of Quarkus","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Data Grid 8","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Fuse 7","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Single Sign-On 7","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-10T00:47:37.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-09-10T00:47:37.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"See https://github.com/netty/netty/security/advisories/GHSA-rq4j-fc47-9698 for fixed versions and remediation guidance.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"93566","cve":"CVE-2026-93566","epss":"0.003790000","percentile":"0.317550000","score_date":"2026-09-19","updated_at":"2026-09-20 00:14:29"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:amq_broker:7"],"defaultStatus":"affected","packageName":"netty-codec-http","product":"Red Hat AMQ Broker 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:amq_clients:2023"],"defaultStatus":"affected","packageName":"netty-codec-http","product":"Red Hat AMQ Clients","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:camel_quarkus:3"],"defaultStatus":"affected","packageName":"netty-codec-http","product":"Red Hat build of Apache Camel 4 for Quarkus 3","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:camel_spring_boot:4"],"defaultStatus":"affected","packageName":"netty-codec-http","product":"Red Hat build of Apache Camel for Spring Boot 4","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:apicurio_registry:3"],"defaultStatus":"unknown","packageName":"netty-codec-http","product":"Red Hat build of Apicurio Registry 3","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:debezium:3"],"defaultStatus":"affected","packageName":"netty-codec-http","product":"Red Hat build of Debezium 3","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:build_keycloak:"],"defaultStatus":"unknown","packageName":"netty-codec-http","product":"Red Hat Build of Keycloak","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:quarkus:3"],"defaultStatus":"unknown","packageName":"netty-codec-http","product":"Red Hat build of Quarkus","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:jboss_data_grid:8"],"defaultStatus":"unknown","packageName":"netty-codec-http","product":"Red Hat Data Grid 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:jboss_fuse:7"],"defaultStatus":"unknown","packageName":"netty-codec-http","product":"Red Hat Fuse 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7"],"defaultStatus":"unknown","packageName":"netty-codec-http","product":"Red Hat JBoss Enterprise Application Platform 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8"],"defaultStatus":"affected","packageName":"netty-codec-http","product":"Red Hat JBoss Enterprise Application Platform 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:red_hat_single_sign_on:7"],"defaultStatus":"unknown","packageName":"netty-codec-http","product":"Red Hat Single Sign-On 7","vendor":"Red Hat"}],"datePublic":"2026-09-10T00:47:37.000Z","descriptions":[{"lang":"en","value":"A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1035","description":"CWE-1035","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-18T20:12:32.112Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-93566"},{"name":"RHBZ#2536954","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2536954"}],"timeline":[{"lang":"en","time":"2026-09-10T00:47:37.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-10T00:47:37.000Z","value":"Made public."}],"title":"Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line","workarounds":[{"lang":"en","value":"See https://github.com/netty/netty/security/advisories/GHSA-rq4j-fc47-9698 for fixed versions and remediation guidance."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-1035"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-93566","datePublished":"2026-09-18T14:19:29.741Z","dateReserved":"2026-09-18T10:00:52.431Z","dateUpdated":"2026-09-18T20:12:32.112Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-18 15:17:20","lastModifiedDate":"2026-09-18 21:18:47","problem_types":["CWE-1035","CWE-1035 CWE-1035"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93566","Ordinal":"1","Title":"Io.netty/netty-codec-http: netty: http request smuggling due to ","CVE":"CVE-2026-93566","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93566","Ordinal":"1","NoteData":"A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.","Type":"Description","Title":"Io.netty/netty-codec-http: netty: http request smuggling due to "}]}}}