THREAT OPS › Threat News › [GHSA] GHSA-8cfx-wx3q-mh5q (high) — netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
[GHSA] GHSA-8cfx-wx3q-mh5q (high) — netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
GHSA-8cfx-wx3q-mh5q Severity: high CVE: CVE-2026-63124
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
## Summary
`io.netty.incubator:netty-incubator-codec-bhttp` can enter a non-terminating parse loop when a known-length Binary HTTP field section ends exactly after a complete field line. A remote peer that can send Binary HTTP input to a Net
Indicators of compromise
- CVE-2026-63124cve
Original source: https://github.com/advisories/GHSA-8cfx-wx3q-mh5q