Security: netty/netty-incubator-codec-ohttp
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decodingGHSA-4899-mpch-38p3 published
Jul 18, 2026 by normanmaurerHigh -
BinaryHttpParser should enforce limits for variable lengths fieldsGHSA-hmq9-67w8-j5pw published
Jul 18, 2026 by normanmaurerHigh -
BoringSSL HPKE private key bytes exposed through toString() and exception messagesGHSA-2mc4-j865-9q4r published
Jul 12, 2026 by normanmaurerHigh -
Binary HTTP parser unchecked varint length overflow causes decoder crashGHSA-pgrf-4654-3gq8 published
Jul 12, 2026 by normanmaurerModerate -
Binary HTTP parser infinite loop on known-length field section boundaryGHSA-8cfx-wx3q-mh5q published
Jul 12, 2026 by normanmaurerHigh -
[OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of ServiceGHSA-vmr9-j6wf-pmh2 published
Jul 9, 2026 by normanmaurerHigh -
OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream TruncationGHSA-r6fj-869h-4f6q published
Jun 3, 2026 by normanmaurerModerate -
[BoringSSL HPKE] Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory AccessGHSA-32hf-8jw3-v4qq published
Jun 3, 2026 by normanmaurerModerate -
HPKEContext operations may produce empty byte[] on failuresGHSA-f659-372h-6x3x published
May 20, 2026 by normanmaurerModerate -
Absent Input Validation in BinaryHttpParserGHSA-q8f2-hxq5-cp4h published
Jul 18, 2024 by normanmaurerHigh