HTTP/2 and HTTP/3 Vulnerability in Red Hat Products
CVE-2026-93568

7.5HIGH

What is CVE-2026-93568?

A vulnerability has been identified in Red Hat products involving HTTP/2 and HTTP/3. Specifically, Extended CONNECT requests are incorrectly downgraded to standard CONNECT requests. This mismanagement can lead to unexpected behavior concerning network protocols and may expose systems to potential security risks. Users of affected products should assess the impact and apply the relevant security measures as necessary.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.