CVE-2026-61827High▾ Twilightnetty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
We don't enforce any limits for the encoded variable lengths that are used for fields. As the remote peer controls these it's easy for the remote peer to have us buffer data forever and so ultimately OOM.
io.netty.incubator:netty-incubator-codec-bhttp <= 0.0.22.FinalUpgrade to a patched release:
io.netty.incubator:netty-incubator-codec-bhttp 0.0.23.FinalConnected by shared product, vendor, weakness, or advisory.
CVE-2026-63124High· 7.5netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
CVE-2026-63202High· 7.5netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
CVE-2026-61799Medium· 5.3netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
CVE-2026-59902High· 7.5Netty is an asynchronous, event-driven network application framework
CVE-2026-44250High· 7.5Netty is a network application framework for development of protocol servers and clients
CVE-2026-44890High· 7.5Netty is a network application framework for development of protocol servers and clients