<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-93567 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-93567/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 18:07:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-93567/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Translation of HTTP/1 CONNECT to HTTP/2 Headers</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93567/</link><pubDate>Fri, 18 Sep 2026 18:07:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93567/</guid><description>A vulnerability exists where HTTP/1 authority-form CONNECT requests are incorrectly translated into malformed HTTP/2 CONNECT requests, allowing for attacker control over the :authority header and potential request smuggling.</description><content:encoded><![CDATA[<p>CVE-2026-93567 describes a vulnerability in how certain proxying mechanisms handle the translation between HTTP/1 authority-form CONNECT requests and HTTP/2 CONNECT requests. When an HTTP/1 request is processed, the system may improperly translate it, resulting in a malformed HTTP/2 CONNECT request where the :authority pseudo-header is controlled by the input provided in the original Host header or request line. This flaw can be leveraged by an attacker to manipulate the :authority header, potentially bypassing security controls, routing restrictions, or authentication mechanisms enforced by downstream services that rely on accurate header information. Because this impacts the translation logic within proxy components, it is critical for infrastructure teams to review the handling of CONNECT requests in their web application firewalls, load balancers, and reverse proxy configurations.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows for the manipulation of request headers in a way that may bypass security policy enforcement or lead to request smuggling within proxy environments. This impacts any infrastructure relying on HTTP/1 to HTTP/2 protocol transformation, potentially allowing unauthorized access to restricted internal resources or the circumvention of network-level security controls.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Perform a security audit of all load balancers, proxies, and web servers that perform HTTP/1 to HTTP/2 protocol conversion.</li>
<li>Review proxy configuration logs to identify unusually formatted CONNECT requests or those containing unexpected characters in the authority or host headers.</li>
<li>Prioritize updates from your infrastructure vendors once patches addressing CVE-2026-93567 are released for your specific proxy software.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve-2026-93567</category><category>request-smuggling</category><category>proxy</category><category>vulnerability</category></item></channel></rss>