{"id":"GHSA-vmr9-j6wf-pmh2","summary":"netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service","details":"The **netty-incubator-codec-ohttp** library implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty's `ByteBuf` memory management. When an OHTTP gateway processes encrypted client requests, it allocates a pooled direct (native off-heap) `ByteBuf` to hold the decrypted plaintext before the AEAD tag is verified. If the AEAD tag check fails — meaning the ciphertext is invalid — the decryption method throws a `CryptoException`, but the allocated buffer is never released because no `try/finally` block guards the allocation.","aliases":["CVE-2026-54251"],"modified":"2026-08-20T18:48:08.821915Z","published":"2026-08-20T18:39:50Z","database_specific":{"cwe_ids":["CWE-664"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-20T18:39:50Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/netty/netty-incubator-codec-ohttp/security/advisories/GHSA-vmr9-j6wf-pmh2"},{"type":"PACKAGE","url":"https://github.com/netty/netty-incubator-codec-ohttp"},{"type":"WEB","url":"https://github.com/netty/netty-incubator-codec-ohttp/releases/tag/netty-incubator-codec-parent-ohttp-0.0.23.Final"}],"affected":[{"package":{"name":"io.netty.incubator:netty-incubator-codec-ohttp","ecosystem":"Maven","purl":"pkg:maven/io.netty.incubator/netty-incubator-codec-ohttp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.23.Final"}]}],"versions":["0.0.1.Final","0.0.10.Final","0.0.11.Final","0.0.12.Final","0.0.13.Final","0.0.14.Final","0.0.15.Final","0.0.16.Final","0.0.17.Final","0.0.18.Final","0.0.19.Final","0.0.2.Final","0.0.20.Final","0.0.21.Final","0.0.22.Final","0.0.3.Final","0.0.4.Final","0.0.5.Final","0.0.6.Final","0.0.7.Final","0.0.8.Final","0.0.9.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-vmr9-j6wf-pmh2/GHSA-vmr9-j6wf-pmh2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}