Loading market data...
← Back to CVE feed

CVE-2026-93562

MEDIUM CVSS 6.5 View on NVD ↗

Description

A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP requests, potentially bypassing security controls or accessing unauthorized resources.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Published: Sep 18, 2026 21:18 UTC Modified: Sep 18, 2026 21:18 UTC