Skip to content
Red HatCVE-2026-93573

Red Hat Netty: request smuggling

Medium6.5CVE-2026-93573 · Published Sep 18, 2026 · updated Sep 24, 2026

A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat AMQ Broker 7
Product
all versionsNo fix yet
Red Hat AMQ Clients
Product
all versionsNo fix yet
Red Hat Build of Keycloak
Product
all versionsNo fix yet
Red Hat Data Grid 8
Product
all versionsNo fix yet
Red Hat Fuse 7
Product
all versionsNo fix yet
Red Hat JBoss Enterprise Application Platform 7
Product
all versionsNo fix yet
Red Hat JBoss Enterprise Application Platform 8
Product
all versionsNo fix yet
Red Hat Single Sign-On 7
Product
all versionsNo fix yet
Red Hat build of Apache Camel 4 for Quarkus 3
Product
all versionsNo fix yet
Red Hat build of Apache Camel for Spring Boot 4
Product
all versionsNo fix yet
Red Hat build of Apicurio Registry 3
Product
all versionsNo fix yet
Red Hat build of Debezium 3
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat OpenShift Container Platform 4: server-side request forgery
Critical9.3Sep 18
Red Hat Netty: request smuggling
Medium6.5Sep 18
Red Hat Netty: request smuggling
Medium6.5Sep 18
A flaw was found in cockpit-files
Medium6.1Sep 18
Red Hat cockpit-files. This vulnerability: race condition
Medium6.0Sep 18
Red Hat cockpit-files: race condition
Medium6.0Sep 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.