CVE-2026-93579 - Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough)
Brief
CVE ID : CVE-2026-93579
Published : Sept. 18, 2026, 4:38 p. m.
- 17 minutes ago
Description : A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cross an HTTP/2 to HTTP/1. 1 translation boundary, they can be exploited for request smuggling, header injection, or response splitting.
This could lead to unauthorized access, data manipulation, or other security bypasses.
Severity: 6.5
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
