PT-2026-46315 · Netty · Codec-Ohttp
CVSS v4.0
6.6
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
netty incubator codec-ohttp versions prior to 0.0.22.Final
Description
The codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp fails to verify the receipt of a cryptographically-signed final chunk before the outer HTTP body terminates. This allows an on-path adversary, such as the OHTTP relay or a man-in-the-middle on the relay-gateway or relay-client transport, to forward a prefix of a legitimate chunked-OHTTP message cut at a non-final chunk boundary and close the outer body cleanly. This action results in no decryption error or exception within the receiving application.
Recommendations
Update to version 0.0.22.Final.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codec-Ohttp