highVulnerability
CVE-2026-61827
We don't enforce any limits for the encoded variable lengths that are used for fields. As the remote peer controls these it's easy for the remote peer to have us buffer data forever and so ultimately OOM.
Properties
- ghsa_id
- GHSA-hmq9-67w8-j5pw
- summary
- netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
- severity
- high
- cve_id
- CVE-2026-61827
- is_ghsa_only
- false
- ghsa_published
- 2026-08-20T18:43:28Z
- source_url
- https://github.com/advisories/GHSA-hmq9-67w8-j5pw
- ghsa_updated
- 2026-08-20T18:43:29Z
Related Entities (5)
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]maven/io.netty.incubator:netty-incubator-codec-bhttp
AFFECTS (1)
→[Software]maven/io.netty.incubator:netty-incubator-codec-bhttp
HAS_WEAKNESS (2)
→[Weakness]Uncontrolled Resource Consumption
→[Weakness]Allocation of Resources Without Limits or Throttling
Explore deeper with Ninja Signal's threat intelligence graph