{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3a/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:*:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93567"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["cve-2026-93567","request-smuggling","proxy","vulnerability"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-93567 describes a vulnerability in how certain proxying mechanisms handle the translation between HTTP/1 authority-form CONNECT requests and HTTP/2 CONNECT requests. When an HTTP/1 request is processed, the system may improperly translate it, resulting in a malformed HTTP/2 CONNECT request where the :authority pseudo-header is controlled by the input provided in the original Host header or request line. This flaw can be leveraged by an attacker to manipulate the :authority header, potentially bypassing security controls, routing restrictions, or authentication mechanisms enforced by downstream services that rely on accurate header information. Because this impacts the translation logic within proxy components, it is critical for infrastructure teams to review the handling of CONNECT requests in their web application firewalls, load balancers, and reverse proxy configurations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for the manipulation of request headers in a way that may bypass security policy enforcement or lead to request smuggling within proxy environments. This impacts any infrastructure relying on HTTP/1 to HTTP/2 protocol transformation, potentially allowing unauthorized access to restricted internal resources or the circumvention of network-level security controls.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform a security audit of all load balancers, proxies, and web servers that perform HTTP/1 to HTTP/2 protocol conversion.\u003c/li\u003e\n\u003cli\u003eReview proxy configuration logs to identify unusually formatted CONNECT requests or those containing unexpected characters in the authority or host headers.\u003c/li\u003e\n\u003cli\u003ePrioritize updates from your infrastructure vendors once patches addressing CVE-2026-93567 are released for your specific proxy software.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T18:07:14Z","date_published":"2026-09-18T18:07:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93567/","summary":"A vulnerability exists where HTTP/1 authority-form CONNECT requests are incorrectly translated into malformed HTTP/2 CONNECT requests, allowing for attacker control over the :authority header and potential request smuggling.","title":"Improper Translation of HTTP/1 CONNECT to HTTP/2 Headers","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93567/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:*:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}