Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat AMQ Broker 7 — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Red Hat AMQ Broker 7, with AI-generated Chinese analysis, references, and POCs.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-93579 Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough) CWE-1035 6.5 Medium 2026-09-18
CVE-2026-93573 Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked validation and enable request smuggling CWE-444 6.5 Medium 2026-09-18
CVE-2026-93568 Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended connect requests are downgraded as regular connect requests CWE-20 7.5 High 2026-09-18
CVE-2026-93569 Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authority, overriding the request-target authority CWE-444 8.2 High 2026-09-18
CVE-2026-93567 Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authority CWE-20 7.5 High 2026-09-18
CVE-2026-93566 Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line CWE-1035 6.5 Medium 2026-09-18
CVE-2026-93565 Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte CWE-1035 7.5 High 2026-09-18
CVE-2026-93564 Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881) CWE-1035 7.5 High 2026-09-18
CVE-2026-93558 Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service CWE-1035 7.5 High 2026-09-18
CVE-2026-93492 Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size CWE-1035 5.3 Medium 2026-09-18
CVE-2026-93491 Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 pipeline queue CWE-770 7.5 High 2026-09-18
CVE-2026-93488 Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streams CWE-770 7.5 High 2026-09-18
CVE-2026-93575 Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder CWE-1035 7.5 High 2026-09-18
CVE-2026-84218 Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix) CWE-184 8.1 High 2026-09-01

All 14 known CVE vulnerabilities affecting Red Hat AMQ Broker 7 with full Chinese analysis, references, and POCs where available.