Vulnerability Description
The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received before the outer HTTP body terminates. An on-path adversary (the OHTTP relay itself, or any MITM on the relay↔gateway or relay↔client transport) can forward a prefix of a legitimate chunked-OHTTP message—cut at a non-final chunk boundary—and close the outer body cleanly, producing no decryption error and no exception in the receiving application. Version 0.0.22.Final fixes the issue.
Related Weaknesses (CWE)
References
- https://github.com/netty/netty-incubator-codec-ohttp/commit/28f977f293591a4e837b
- https://github.com/netty/netty-incubator-codec-ohttp/security/advisories/GHSA-r6
FAQ
What is CVE-2026-48480?
CVE-2026-48480 is a documented vulnerability. The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptograph...
How severe is CVE-2026-48480?
CVSS scoring is not yet available for CVE-2026-48480. Check NVD for updates.
Is there a patch for CVE-2026-48480?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.