MAVEN · AUGUST 2026 · EARLY WARNING

netty-incubator-codec-ohttp Vulnerability: Early Warning and Mitigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Affected component
netty-incubator-codec-ohttp (maven)
Patched version
Not yet available
GHSA-4899-MPCH-38P3

An unauthenticated CPU-exhaustion DoS vulnerability has been reported in the netty-incubator-codec-ohttp package. This issue allows for potential DoS attacks via an infinite loop in field-section decoding.

What happened

The netty-incubator-codec-ohttp package, specifically versions from HEAD d3f2b49 (release 0.0.22.Final + 3 commits), contains a high-severity vulnerability. This vulnerability enables an unauthenticated attacker to execute a CPU-exhaustion DoS attack by exploiting an infinite loop in the field-section decoding process. The issue was first flagged on 2026-08-20T18:43:38+00:00 and is currently under investigation.

The vulnerability, tracked as GHSA-4899-MPCH-38P3, has a CVSS score of 7.5, indicating a significant risk. Although there is no evidence of exploitation in the wild at this time, the potential impact on system availability is high. Users of the affected package versions should take immediate steps to assess their exposure and implement mitigations as recommended.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If netty-incubator-codec-ohttp is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are potentially affected if you are using the netty-incubator-codec-ohttp package in versions from HEAD d3f2b49 (release 0.0.22.Final + 3 commits).

What should I do right now?

Monitor your systems for DoS attacks, review your usage of the affected package, and stay informed by checking the primary sources for updates.

Is there an official patch available?

No official patch has been published yet. Continue to monitor the sources for updates on any available fixes.

Sources

Join the 0Day waitlist →

← Back to all threats