rootpwn

critical · CVSS v3 9.8

CVE-2026-93567

HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority

Description

HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority

Scores

Severity
critical
CVSS v2
7.8
CVSS v3
9.8
CVSS v4
EPSS

← All CVEs