Memory Leak Vulnerability in OHTTP Gateway of Netty Incubator Product
CVE-2026-54251

8.7HIGH

Key Information:

Vendor

Netty

Vendor
CVE Published:
15 September 2026

What is CVE-2026-54251?

The OHTTP implementation in the netty-incubator-codec-ohttp package has a vulnerability that allows for native off-heap memory to be leaked under certain conditions. When an invalid encrypted request is processed, the decryption routine allocates a ByteBuf for storing decrypted data before verifying the authenticity of the data. If the data verification fails and throws a CryptoException, the allocated memory is not released properly due to a missing try/finally block, leading to potential server instability from excessive memory consumption. This issue has been resolved in version 0.0.23.Final, which addresses the memory management flaw to prevent leaks during decryption errors. It underscores the importance of proper memory handling in security protocols.

Affected Version(s)

netty-incubator-codec-ohttp < 0.0.23.Final

netty-incubator-codec-ohttp < 0.0.23.Final

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.