GHSA-vmr9-j6wf-pmh2
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
Quick fix
GHSA-vmr9-j6wf-pmh2 — io.netty.incubator:netty-incubator-codec-ohttp: upgrade to the fixed version with the command below.
# pom.xml: bump <version>0.0.23.Final</version> for io.netty.incubator:netty-incubator-codec-ohttp Details
The **netty-incubator-codec-ohttp** library implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty's `ByteBuf` memory management. When an OHTTP gateway processes encrypted client requests, it allocates a pooled direct (native off-heap) `ByteBuf` to hold the decrypted plaintext before the AEAD tag is verified. If the AEAD tag check fails — meaning the ciphertext is invalid — the decryption method throws a `CryptoException`, but the allocated buffer is never released because no `try/finally` block guards the allocation.
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 0.0.23.Final # pom.xml: bump <version>0.0.23.Final</version> for io.netty.incubator:netty-incubator-codec-ohttp