THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pgrf-4654-3gq8 (medium) — netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

[GHSA] GHSA-pgrf-4654-3gq8 (medium) — netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

medgithub_advisoriesPublished 2026-08-20

GHSA-pgrf-4654-3gq8 Severity: medium CVE: CVE-2026-61799

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

## Summary

`io.netty.incubator:netty-incubator-codec-bhttp` uses attacker-controlled Binary HTTP variable-length integers as `long` values but accumulates them into `int` offsets. Large valid varint lengths wrap the internal offset negati

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pgrf-4654-3gq8