{"id":"GHSA-f659-372h-6x3x","summary":"netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures","details":"HKDF_expand: returns non-NULL on failure. The byte[] is filled with zeros and has no way to distinguish success from failure. Since this output is used as HKDF key material for the response AEAD, a  failure silently produces an all-zero key.\n\nWhen EVP_HPKE_CTX_export fails it also returns an empty byte[] array filled with zeros. This byte[] feeds directly into OHttpCrypto.createResponseAEAD(...).  A silent all-zero export secret would produce a deterministic, attacker-predictable AEAD key.","aliases":["CVE-2026-41207"],"modified":"2026-06-09T12:00:14.063894871Z","published":"2026-05-26T23:08:26Z","database_specific":{"cwe_ids":["CWE-330"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-26T23:08:26Z","nvd_published_at":"2026-06-04T18:16:30Z"},"references":[{"type":"WEB","url":"https://github.com/netty/netty-incubator-codec-ohttp/security/advisories/GHSA-f659-372h-6x3x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41207"},{"type":"WEB","url":"https://github.com/netty/netty-incubator-codec-ohttp/commit/3d3b4e527fc82ad0fe3db1af951ffd0ec9a10680"},{"type":"PACKAGE","url":"https://github.com/netty/netty-incubator-codec-ohttp"}],"affected":[{"package":{"name":"io.netty.incubator:netty-incubator-codec-ohttp","ecosystem":"Maven","purl":"pkg:maven/io.netty.incubator/netty-incubator-codec-ohttp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.21.Final"}]}],"versions":["0.0.1.Final","0.0.10.Final","0.0.11.Final","0.0.12.Final","0.0.13.Final","0.0.14.Final","0.0.15.Final","0.0.16.Final","0.0.17.Final","0.0.18.Final","0.0.19.Final","0.0.2.Final","0.0.20.Final","0.0.3.Final","0.0.4.Final","0.0.5.Final","0.0.6.Final","0.0.7.Final","0.0.8.Final","0.0.9.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-f659-372h-6x3x/GHSA-f659-372h-6x3x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}