THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8cfx-wx3q-mh5q (high) — netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

[GHSA] GHSA-8cfx-wx3q-mh5q (high) — netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

medgithub_advisoriesPublished 2026-08-20

GHSA-8cfx-wx3q-mh5q Severity: high CVE: CVE-2026-63124

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

## Summary

`io.netty.incubator:netty-incubator-codec-bhttp` can enter a non-terminating parse loop when a known-length Binary HTTP field section ends exactly after a complete field line. A remote peer that can send Binary HTTP input to a Net

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8cfx-wx3q-mh5q