VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions

2026-07-17T20:52:12Z9df1d8c217b0dd0ea91bea5da1fefbfd3a58733a44c688dcf1bc712d8e04942c
androidcryptographydenial-of-servicedeserializationed25519flow-controlftp-pasvgnu-wgethttp2ioctlkernelmemory-exhaustionnode-forgepickleprivilege-escalationremote-code-executionrsa-pkcs1-v1.5sglangsignature-forgeryssrftdeio64.systls-bypass','javascript-injection','payrange','authentication-b​webviewwindows-driverzeromq

What happened

This collection describes multiple, distinct vulnerabilities across widely used software and libraries. Highlights include: an HTTP/2 server-side denial-of-service via stalled flow-control that can exhaust memory/buffers; an unauthenticated Pickle deserialization RCE in SGLang (CVE-2026-14890) via an exposed ZeroMQ PULL socket; an unprotected IOCTL in Pegatron tdeio64.sys enabling arbitrary kernel read/write and SYSTEM privilege escalation (CVE-2026-14961, CVE-2026-14960); signature-forgery flaws in node-forge for RSA-PKCS#1 v1.5 and Ed25519 (CVE-2026-33894, CVE-2026-33895); an FTP PASV IP/SS​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
9df1d8c217b0dd0ea91bea5da1fefbfd3a58733a44c688dcf1bc712d8e04942c
Enrichment time
2026-07-17T20:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.