Junglewise Threat Intelligence

CVE-2026-93565: Netty RtspDecoder method-token smuggling in RTSP parsing

CVE-2026-93565 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: Netty. Vendors: Netty.

Executive brief

Netty is a popular Java networking library used by many streaming and proxy services to handle real-time streaming protocol (RTSP) traffic. A flaw in the RTSP decoder allows attackers to craft malicious requests that bypass method-based access controls and sneak unauthorized commands through RTSP proxies, making them appear legitimate to backend systems.

Technical details

The vulnerability exists in Netty's RtspDecoder component, specifically in the `RtspMethods.valueOf()` function, which incorrectly strips trailing control bytes from RTSP method tokens during request parsing. This allows an attacker to send a specially crafted RTSP request that exploits improper method-token parsing, leading to method-token smuggling. The attack requires network connectivity to an RTSP service using vulnerable Netty versions and no authentication is required. An attacker can bypass method-based access controls and launder malicious requests through Netty-based RTSP proxies so that backend systems interpret them as legitimate traffic. A patch is expected to correct the improper control byte stripping logic.

Affected products

  • Netty Netty <UNKNOWN>

Timeline

  • 2026-09-18: disclosed

References

Related threats