The netty-incubator-codec-ohttp library implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty's ByteBuf memory management. When an OHTTP gateway processes encrypted client requests, it allocates a pooled direct (native off-heap) ByteBuf to hold the decrypted plaintext before the AEAD tag is verified. If the AEAD tag check fails — meaning the ciphertext is invalid — the decryption method throws a CryptoException, but the allocated buffer is never released because no try/finally block guards the allocation.
{
"cwe_ids": [
"CWE-664"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-20T18:39:50Z",
"nvd_published_at": null,
"severity": "HIGH"
}