{"id":"CVE-2026-93573","published":"2026-09-18T15:17:21.020","lastModified":"2026-09-24T11:17:00.790","description":"A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwes":["CWE-444"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:69440","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:69470","tags":[]},{"url":"https://access.redhat.com/security/cve/CVE-2026-93573","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2536964","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}