Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-59900

CVE-2026-59900: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium6.5

    Medium [CVE-2026-59900] Improper header neutralization in netty-codec-http2

    CVE-2026-59900Source published Source updated

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. A flaw was found in Netty's netty-codec-http2 component. The HTTP/2 encoder does not properly handle special characters in HTTP headers. This vulnerability allows a remote attacker to craft…

    Affected products in this advisory
    • Red Hat build of Quarkus 3.27.4.SP3
    • Red Hat build of Quarkus 3.33.2.SP3
    • Cryostat 4
    • OpenShift Serverless

    16 more entries in the full advisory.

    Source-reported affected versions
    • < 4.1.136.Final
    • < 4.2.16.Final
    Source-reported fixed versions
    • 4.1.136
    • 4.2.16
    • netty-codec-http2
    • RHSA-2026:47189

    1 more entries in the full advisory.

    Mitigation guidance
    • - Upgrade `netty-codec-http2` to version 4.1.136.Final (4.1.x branch) or 4.2.16.Final (4.2.x branch). - If upgrading is not immediately possible, ensure that HTTP/2 traffic is routed through a reverse proxy or WAF that validates and sanitizes HTTP headers before forwarding to the Netty-based application.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery