Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
See https://github.com/netty/netty/security/advisories/GHSA-45h4-vhwh-fmhg for fixed versions and remediation guidance.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Io.netty
Io.netty netty-codec-http2 Redhat build Of Apache Camel For Quarkus Redhat build Of Apache Camel For Spring Boot Redhat build Of Apicurio Registry Redhat build Of Debezium 3 Redhat build Of Keycloak Redhat build Of Quarkus Redhat data Grid 8 Redhat quay 3 Redhat single Sign-on |
|
| Vendors & Products |
Io.netty
Io.netty netty-codec-http2 Redhat build Of Apache Camel For Quarkus Redhat build Of Apache Camel For Spring Boot Redhat build Of Apicurio Registry Redhat build Of Debezium 3 Redhat build Of Keycloak Redhat build Of Quarkus Redhat data Grid 8 Redhat quay 3 Redhat single Sign-on |
Mon, 21 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Redhat quarkus
|
|
| References |
|
Sat, 19 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority | A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit this by supplying a different Host header, leading to a malformed HTTP/2 CONNECT request. This can bypass security controls such as tunnel allow-lists or egress policies, resulting in integrity loss. |
Fri, 18 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority | |
| Title | Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authority | |
| First Time appeared |
Redhat
Redhat amq Broker Redhat apicurio Registry Redhat build Keycloak Redhat camel Quarkus Redhat camel Spring Boot Redhat debezium Redhat jboss Data Grid Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat quarkus Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:/a:redhat:amq_broker:7 cpe:/a:redhat:apicurio_registry:3 cpe:/a:redhat:build_keycloak: cpe:/a:redhat:camel_quarkus:3 cpe:/a:redhat:camel_spring_boot:4 cpe:/a:redhat:debezium:3 cpe:/a:redhat:jboss_data_grid:8 cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:quarkus:3 cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat amq Broker Redhat apicurio Registry Redhat build Keycloak Redhat camel Quarkus Redhat camel Spring Boot Redhat debezium Redhat jboss Data Grid Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat quarkus Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-21T20:51:34.080Z
Reserved: 2026-09-18T10:02:05.097Z
Link: CVE-2026-93567
Updated: 2026-09-21T19:48:37.942Z
Status : Awaiting Analysis
Published: 2026-09-18T15:17:20.450
Modified: 2026-09-21T21:17:18.387
Link: CVE-2026-93567
OpenCVE Enrichment
Updated: 2026-09-21T19:25:24Z