VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
2026-07-16T20:52:11Z•c042a7fb0acdb1a5e64c3d6fb140af844b19a2d4b671735661bd55b5fd4ef275
DoSSETTINGS_INITIAL_WINDOW_SIZEWINDOW_UPDATEdenial-of-serviceflow-controlhttp2memory-exhaustionnetwork-vectorprotocol-abuseremoteresource-exhaustionserver
What happened
Multiple HTTP/2 server implementations fail to limit resource consumption when clients stall outbound flow control (e.g., by withholding WINDOW_UPDATE or advertising SETTINGS_INITIAL_WINDOW_SIZE = 0). An unauthenticated remote attacker can open many concurrent streams requesting large responses; the server may continue to generate and buffer response bodies, leading to excessive memory/swap use, worker/connection exhaustion, degraded availability, and potentially crashes. The issue is a network-reachable denial-of-service via stalled flow-control conditions.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- c042a7fb0acdb1a5e64c3d6fb140af844b19a2d4b671735661bd55b5fd4ef275
- Enrichment time
- 2026-07-16T20:52:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.