VYPR
Medium severity6.5NVD Advisory· Published Sep 18, 2026

CVE-2026-93562

CVE-2026-93562

Description

A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP requests, potentially bypassing security controls or accessing unauthorized resources.

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.