<Vulnerability name="CVE-2026-93576">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-10T00:53:44</PublicDate>
    <Bugzilla id="2536968" url="https://bugzilla.redhat.com/show_bug.cgi?id=2536968" xml:lang="en:us">
io.netty/netty-codec-smtp: Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-93</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this field, can embed CR/LF characters to inject arbitrary SMTP commands. This can lead to SMTP command smuggling, allowing for unauthorized email relay or spoofing of sender/recipient addresses. While the impact is significant, the real-world exploitability is considered lower as applications typically do not place user-controlled data in the command-name field.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this field, can embed CR/LF characters to inject arbitrary SMTP commands. This can lead to SMTP command smuggling, allowing for unauthorized email relay or spoofing of sender/recipient addresses. While the impact is significant, the real-world exploitability is considered lower as applications typically do not place user-controlled data in the command-name field.
    </Details>
    <Statement xml:lang="en:us">
Important: A CRLF injection vulnerability in Netty's `netty-codec-smtp` component allows for SMTP command smuggling. This flaw enables attackers to inject arbitrary SMTP commands, potentially leading to unauthorized relay or spoofing. However, exploitation is limited to applications that route untrusted input into the SMTP command-name field, which is an uncommon configuration, reducing its overall reachability.
    </Statement>
    <Mitigation xml:lang="en:us">
See https://github.com/netty/netty/security/advisories/GHSA-5vh9-c45f-rf7p for fixed versions and remediation guidance.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:camel_spring_boot:4">
        <ProductName>Red Hat build of Apache Camel for Spring Boot 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>netty-codec-smtp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_fuse:7">
        <ProductName>Red Hat Fuse 7</ProductName>
        <FixState>Affected</FixState>
        <PackageName>netty-codec-smtp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>jboss-eap-7/eap74-els-openjdk11-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>jboss-eap-7/eap74-els-openjdk17-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>jboss-eap-7/eap74-els-openjdk8-openshift-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>netty-codec-smtp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:red_hat_single_sign_on:7">
        <ProductName>Red Hat Single Sign-On 7</ProductName>
        <FixState>Affected</FixState>
        <PackageName>netty-codec-smtp</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-93576
https://nvd.nist.gov/vuln/detail/CVE-2026-93576
    </References>
</Vulnerability>