Impact
Netty’s OHTTP Codec allocates a pooled direct ByteBuf for decrypted plaintext before verifying the AEAD tag. When a decryption fails because of an invalid authentication tag, the CryptoException is thrown and the buffer is never released because the allocation lacks a try/finally guard. Each malformed request consumes off‑heap native memory, and repeated attempts can exhaust the gateway’s memory pool, causing it to stop serving traffic. This flaw is an instance of improper memory management (CWE‑664) and results solely in a denial of service; it does not expose confidential data or allow code execution. The issue is resolved with the release of netty‑incubator‑codec‑ohttp‑0.0.23.Final.
Affected Systems
The vulnerability affects the Netty Incubator OHTTP Codec (netty‑incubator‑codec‑ohttp) from the io.netty.incubator and netty vendor groups. All releases prior to version 0.0.23.Final are vulnerable; versions 0.0.23.Final and later contain the fix.
Risk and Exploitability
The CVSS score of 8.7 places the vulnerability in the high severity range. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Since the gateway processes network traffic, an attacker could remotely send repeated malformed OHTTP requests to trigger the memory leak. The flaw can be exploited by sending a large volume of encrypted requests with invalid authentication tags, consuming native off‑heap memory until the gateway can no longer process further traffic. Once patched in version 0.0.23.Final, the allocation is guarded by a try/finally block and the buffer is released on failure, eliminating the exploitability path.
OpenCVE Enrichment
Github GHSA