CVE-2026-59900
CVE-2026-59900: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-59900] Improper header neutralization in netty-codec-http2
CVE-2026-59900Source published Source updated
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. A flaw was found in Netty's netty-codec-http2 component. The HTTP/2 encoder does not properly handle special characters in HTTP headers. This vulnerability allows a remote attacker to craft…
- Affected products in this advisory
- Red Hat build of Quarkus 3.27.4.SP3
- Red Hat build of Quarkus 3.33.2.SP3
- Cryostat 4
- OpenShift Serverless
16 more entries in the full advisory.
- Source-reported affected versions
- < 4.1.136.Final
- < 4.2.16.Final
- Source-reported fixed versions
- 4.1.136
- 4.2.16
- netty-codec-http2
- RHSA-2026:47189
1 more entries in the full advisory.
- Mitigation guidance
- - Upgrade `netty-codec-http2` to version 4.1.136.Final (4.1.x branch) or 4.2.16.Final (4.2.x branch). - If upgrading is not immediately possible, ensure that HTTP/2 traffic is routed through a reverse proxy or WAF that validates and sanitizes HTTP headers before forwarding to the Netty-based application.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.