rootpwn

critical · CVSS v3 9.8

CVE-2026-93569

HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority

Description

HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority

Scores

Severity
critical
CVSS v2
8.5
CVSS v3
9.8
CVSS v4
EPSS

← All CVEs