HIGH 7.5 GitHub
CVE-2026-63202
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
# BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
- **ID:** BHTTP-LOOP-001
- **Severity:** High
- **CVSS v3.1:** 7.5 — `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`
- **CWE:** CWE-835 (Loop with Unreachable Exit Condition) — secondary CWE-400 (Uncontrolled Resource Consumption)
- **Affected component:** `codec-bhttp` → `io.netty.incubator.codec.bhttp.BinaryHttpParser#readFieldSection`, file `codec-bhttp/src/main/java/io/netty/incubator/codec/bht
Affected Products
- maven/io.netty.incubator:netty-incubator-codec-bhttp <= 0.0.22.Final
References
- https://github.com/advisories/GHSA-4899-mpch-38p3
- https://github.com/netty/netty-incubator-codec-ohttp/security/advisories/GHSA-4899-mpch-38
- https://github.com/netty/netty-incubator-codec-ohttp/releases/tag/netty-incubator-codec-pa
- https://github.com/advisories/GHSA-4899-mpch-38p3
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-20 via GitHub. Affected: maven/io.netty.incubator:netty-incubator-codec-bhttp <= 0.0.22.Final.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.