🔐 CVE Alert

CVE-2026-48480

UNKNOWN 0.0

netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received before the outer HTTP body terminates. An on-path adversary (the OHTTP relay itself, or any MITM on the relay↔gateway or relay↔client transport) can forward a prefix of a legitimate chunked-OHTTP message—cut at a non-final chunk boundary—and close the outer body cleanly, producing no decryption error and no exception in the receiving application. Version 0.0.22.Final fixes the issue.

CWE CWE-325
Vendor netty
Product netty-incubator-codec-ohttp
Published Jun 4, 2026
Last Updated Jun 4, 2026
Stay Ahead of the Next One

Get instant alerts for netty netty-incubator-codec-ohttp

Be the first to know when new unknown vulnerabilities affecting netty netty-incubator-codec-ohttp are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

netty / netty-incubator-codec-ohttp
< 0.0.22.Final

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/netty/netty-incubator-codec-ohttp/security/advisories/GHSA-r6fj-869h-4f6q github.com: https://github.com/netty/netty-incubator-codec-ohttp/commit/28f977f293591a4e837bd59ceb441f9f70349915