← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 18, 2026 · 16:38via CVEFeed

CVE-2026-93579 - Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough)

Brief

CVE ID : CVE-2026-93579

Published : Sept. 18, 2026, 4:38 p. m.

  • 17 minutes ago

Description : A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cross an HTTP/2 to HTTP/1. 1 translation boundary, they can be exploited for request smuggling, header injection, or response splitting.

This could lead to unauthorized access, data manipulation, or other security bypasses.

Severity: 6.5

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→