highVulnerability

CVE-2026-61827

We don't enforce any limits for the encoded variable lengths that are used for fields. As the remote peer controls these it's easy for the remote peer to have us buffer data forever and so ultimately OOM.

Properties

ghsa_id
GHSA-hmq9-67w8-j5pw
summary
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
severity
high
cve_id
CVE-2026-61827
is_ghsa_only
false
ghsa_published
2026-08-20T18:43:28Z
source_url
https://github.com/advisories/GHSA-hmq9-67w8-j5pw
ghsa_updated
2026-08-20T18:43:29Z

Related Entities (5)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]maven/io.netty.incubator:netty-incubator-codec-bhttp

AFFECTS (1)

[Software]maven/io.netty.incubator:netty-incubator-codec-bhttp

HAS_WEAKNESS (2)

[Weakness]Uncontrolled Resource Consumption
[Weakness]Allocation of Resources Without Limits or Throttling

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-61827 — Ninja Signal Threat Intelligence | Ninja Signal