Out-of-bounds Read Affecting io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl package, versions [,0.0.22.Final)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-IONETTYINCUBATOR-17276323
  • published10 Jun 2026
  • disclosed4 Jun 2026
  • creditUnknown

Introduced: 4 Jun 2026

CVE-2026-48040  (opens in a new tab)
CWE-125  (opens in a new tab)

How to fix?

Upgrade io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl to version 0.0.22.Final or higher.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Read in the fallback process for deriving native memory addresses when hasMemoryAddress() returns false and sun.misc.Unsafe is unavailable. An attacker can corrupt memory of concurrent connections and disclose contents of adjacent pooled direct buffers by sending crafted OHTTP requests.

Note:

This is only exploitable if the JVM is configured to disable Unsafe access (e.g., with -Dio.netty.noUnsafe=true), a SecurityManager restricts Unsafe access, or when running on non-HotSpot JVMs.

CVSS Base Scores

version 4.0
version 3.1