← Back

CVE-2026-54340

nvd nist
Published: Jul 17, 2026Modified: Aug 5, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling. Amplified decoded header state can be retained by stalled HTTP/2 streams, and depending on the configuration, additional limits are needed to bound decoded header state and prevent attack. This issue has been fixed by commit 9265bdd.

Affected (1)

Products: H2o: H2o
1 product
H2o
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2026-05-29 to 2026-06-04

References (2)

Source: security-advisories@github.com
Third Party Advisory

Timeline

No history available yet.