VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions

2026-07-16T20:52:11Zc042a7fb0acdb1a5e64c3d6fb140af844b19a2d4b671735661bd55b5fd4ef275
DoSSETTINGS_INITIAL_WINDOW_SIZEWINDOW_UPDATEdenial-of-serviceflow-controlhttp2memory-exhaustionnetwork-vectorprotocol-abuseremoteresource-exhaustionserver

What happened

Multiple HTTP/2 server implementations fail to limit resource consumption when clients stall outbound flow control (e.g., by withholding WINDOW_UPDATE or advertising SETTINGS_INITIAL_WINDOW_SIZE = 0). An unauthenticated remote attacker can open many concurrent streams requesting large responses; the server may continue to generate and buffer response bodies, leading to excessive memory/swap use, worker/connection exhaustion, degraded availability, and potentially crashes. The issue is a network-reachable denial-of-service via stalled flow-control conditions.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
c042a7fb0acdb1a5e64c3d6fb140af844b19a2d4b671735661bd55b5fd4ef275
Enrichment time
2026-07-16T20:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions · Baitaphish