CVE-2026-93564: Red Hat Amq Broker 7
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory exhaustion, resulting in a Denial of Service (DoS) for the affected system.
Affected products
- Red Hat Red Hat Amq Broker 7
- Red Hat Red Hat Build Of Apache Camel 3.33.3.sp2: before 4.1.138.Final-redhat-00001 (fixed in 4.1.138.Final-redhat-00001)
- Red Hat Red Hat Build Of Apache Camel 4 For Quarkus 3
- Red Hat Red Hat Build Of Apache Camel For Spring Boot 4
- Red Hat Red Hat Build Of Apicurio Registry 3
- Red Hat Red Hat Build Of Debezium 3
- Red Hat Red Hat Build Of Keycloak
- Red Hat Red Hat Build Of Quarkus 3.27.5.sp2
- Red Hat Red Hat Build Of Quarkus 3.33.3.sp2
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat Single Sign-On 7
Published 2026-09-18. Last modified 2026-10-10.