{"id":"CVE-2026-93567","published":"2026-09-18T15:17:20.450","lastModified":"2026-09-22T19:16:58.203","description":"A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit this by supplying a different Host header, leading to a malformed HTTP/2 CONNECT request. This can bypass security controls such as tunnel allow-lists or egress policies, resulting in integrity loss.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwes":["CWE-20"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:69440","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:69470","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:70257","tags":[]},{"url":"https://access.redhat.com/security/cve/CVE-2026-93567","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2536955","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}