CVE-2026-41207: netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures

Published May 26, 2026
·
Updated

HKDFexpand: returns non-NULL on failure. The byte[] is filled with zeros and has no way to distinguish success from failure. Since this output is used as HKDF key material for the response AEAD, a failure silently produces an all-zero key.

When EVPHPKECTXexport fails it also returns an empty byte[] array filled with zeros. This byte[] feeds directly into OHttpCrypto.createResponseAEAD(...). A silent all-zero export secret would produce a deterministic, attacker-predictable AEAD key.

Other sources

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDFexpand returns non-NULL on failure. The byte[] is filled with zeros and has no way to distinguish success from failure. Since this output is used as HKDF key material for the response AEAD, a failure silently produces an all-zero key. When EVPHPKECTXexport fails it also returns an empty byte[] array filled with zeros. This byte[] feeds directly into OHttpCrypto.createResponseAEAD(...). A silent all-zero export secret would produce a deterministic, attacker-predictable AEAD key. Version 0.0.21.Final patches the issue.

MITRE

Affected Software

2 affected componentsFixes available
maven/io.netty.incubator:netty-incubator-codec-ohttp<0.0.21.Final
0.0.21.Final
Netty netty-incubator-codec-ohttp<0.0.21

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/io.netty.incubator:netty-incubator-codec-ohttp to a version that resolves this vulnerability.

    Fixed in 0.0.21.Final
  2. Upgrade

    Upgrade netty-incubator-codec-bhttp / netty-incubator-codec-ohttp (OHttpCrypto.createResponseAEAD / HPKEContext) to a version that resolves this vulnerability.

    Fixed in 0.0.21.Final
  3. Operational

    If you ever produced response AEAD keys using HKDF_expand output or HPKEContext export output that may have silently failed, rotate/recreate any affected keys and invalidate any derived artifacts created from those all-zero/empty byte[] values.

Event History

May 26, 2026
Advisory Published
via GitHub·11:08 PM
Data Sourced
via GitHub·11:08 PM
DescriptionWeaknessAffected Software
Jun 4, 2026
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-41207?

CVE-2026-41207 has a risk score of 52, indicating a moderate severity level.

2

How do I fix CVE-2026-41207?

To fix CVE-2026-41207, update the affected version of the maven/io.netty.incubator:netty-incubator-codec-ohttp library to the latest release that addresses this vulnerability.

3

What are the potential impacts of CVE-2026-41207?

CVE-2026-41207 could lead to the generation of all-zero keys due to silent failures, compromising the security of cryptographic operations.

4

Which software is affected by CVE-2026-41207?

CVE-2026-41207 affects maven/io.netty.incubator:netty-incubator-codec-ohttp and its implementations.

5

Is CVE-2026-41207 a zero-day vulnerability?

CVE-2026-41207 is not classified as a zero-day vulnerability, as it was published on May 26, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203