216.73.217.22

CVE-2026-48480

· Published 04/06/2026 19:16 · Modified 05/06/2026 16:00

Labels: CVE-2026-48480 2026-06-04CVE-2026-48480CWE-325[email protected]

Essential information

Published
04/06/2026 19:16
Modified
05/06/2026 16:00
Author
Creator
CVSS
6.6 MEDIUM (v3) 6.6 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received before the outer HTTP body terminates. An on-path adversary (the OHTTP relay itself, or any MITM on the relay↔gateway or relay↔client transport) can forward a prefix of a legitimate chunked-OHTTP message—cut at a non-final chunk boundary—and close the outer body cleanly, producing no decryption error and no exception in the receiving application. Version 0.0.22.Final fixes the issue.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
netty / codec.bhttp cpe:2.3:a:netty:codec.bhttp:<0.0.22.Final:*:*:*:*:*:*

References