GHSA-hmq9-67w8-j5pw

Suggest an improvement
Source
https://github.com/advisories/GHSA-hmq9-67w8-j5pw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-hmq9-67w8-j5pw/GHSA-hmq9-67w8-j5pw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hmq9-67w8-j5pw
Aliases
  • CVE-2026-61827
Published
2026-08-20T18:43:28Z
Modified
2026-08-20T19:11:03Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
Details

We don't enforce any limits for the encoded variable lengths that are used for fields. As the remote peer controls these it's easy for the remote peer to have us buffer data forever and so ultimately OOM.

Database specific
{
    "cwe_ids":  [
        "CWE-400",
        "CWE-770"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-20T18:43:28Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Maven / io.netty.incubator:netty-incubator-codec-bhttp

Package

Name
io.netty.incubator:netty-incubator-codec-bhttp
View open source insights on deps.dev
Purl
pkg:maven/io.netty.incubator/netty-incubator-codec-bhttp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.23.Final

Affected versions

0.*
0.0.1.Final
0.0.2.Final
0.0.3.Final
0.0.4.Final
0.0.5.Final
0.0.6.Final
0.0.7.Final
0.0.8.Final
0.0.9.Final
0.0.10.Final
0.0.11.Final
0.0.12.Final
0.0.13.Final
0.0.14.Final
0.0.15.Final
0.0.16.Final
0.0.17.Final
0.0.18.Final
0.0.19.Final
0.0.20.Final
0.0.21.Final
0.0.22.Final

Database specific

last_known_affected_version_range
"<= 0.0.22.Final"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-hmq9-67w8-j5pw/GHSA-hmq9-67w8-j5pw.json"