MEDIUM 6.5 NVD
CVE-2026-93562
A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggl
A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP requests, potentially bypassing security controls or accessing unauthorized resources.
References
- https://access.redhat.com/security/cve/CVE-2026-93562
- https://bugzilla.redhat.com/show_bug.cgi?id=2536951
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-09-18 via NVD.
vulnfeed aggregates 14357 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.