Memory Leak Vulnerability in OHTTP Gateway of Netty Incubator Product
CVE-2026-54251
What is CVE-2026-54251?
The OHTTP implementation in the netty-incubator-codec-ohttp package has a vulnerability that allows for native off-heap memory to be leaked under certain conditions. When an invalid encrypted request is processed, the decryption routine allocates a ByteBuf for storing decrypted data before verifying the authenticity of the data. If the data verification fails and throws a CryptoException, the allocated memory is not released properly due to a missing try/finally block, leading to potential server instability from excessive memory consumption. This issue has been resolved in version 0.0.23.Final, which addresses the memory management flaw to prevent leaks during decryption errors. It underscores the importance of proper memory handling in security protocols.
Affected Version(s)
netty-incubator-codec-ohttp < 0.0.23.Final
netty-incubator-codec-ohttp < 0.0.23.Final
