Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-54340

Опубликовано: 17 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling. Amplified decoded header state can be retained by stalled HTTP/2 streams, and depending on the configuration, additional limits are needed to bound decoded header state and prevent attack. This issue has been fixed by commit 9265bdd.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:h2o:h2o:*:*:*:*:*:*:*:*
Версия от 2026-05-29 (включая) до 2026-06-04 (исключая)

EPSS

Процентиль: 20%
0.00279
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
22 дня назад

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling. Amplified decoded header state can be retained by stalled HTTP/2 streams, and depending on the configuration, additional limits are needed to bound decoded header state and prevent attack. This issue has been fixed by commit 9265bdd.

CVSS3: 7.5
debian
22 дня назад

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pr ...

EPSS

Процентиль: 20%
0.00279
Низкий

7.5 High

CVSS3

Дефекты

CWE-400