← Back

CVE-2026-21438

nvd nist
Published: Feb 12, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: security-advisories@github.com (Secondary)

Description

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Closed streams were not removed from an internal session map, preventing garbage collection of their resources. This vulnerability is fixed in v0.10.0.

Affected (1)

1 product
Webtransport Go
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.10.0

References (2)

Source: security-advisories@github.com
ProductRelease Notes

Timeline

No history available yet.