HTTP/1 Host Mismatch Vulnerability in Red Hat Products
CVE-2026-93569

8.2HIGH

What is CVE-2026-93569?

This vulnerability arises from an HTTP/1 absolute-form Host mismatch, which is incorrectly translated to the HTTP/2 :authority header. This misconfiguration can lead to potential issues in request-target authority management, allowing malicious actors to exploit the vulnerability to manipulate request flows within affected Red Hat products. As a result, this could jeopardize the integrity and confidentiality of the data being processed by the systems.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.