Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33814

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

A flaw was found in the HTTP/2 protocol implementation within the Go standard library (golang.org/x/net and net/http/internal/http2). A remote attacker can exploit this vulnerability by sending a specially crafted HTTP/2 SETTINGS frame with the SETTINGS_MAX_FRAME_SIZE parameter set to zero. This malicious frame causes the transport layer to enter an infinite loop of writing CONTINUATION frames, leading to resource exhaustion and a Denial of Service (DoS) condition.

Отчет

This Important denial of service flaw in the Go HTTP/2 protocol implementation allows a remote, unauthenticated attacker to exhaust system resources. By sending a specially crafted HTTP/2 SETTINGS frame with a zero-value SETTINGS_MAX_FRAME_SIZE, the vulnerable Go library enters an infinite loop, impacting the availability of services utilizing HTTP/2.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/addon-manager-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/backplane-rhel9-operatorUnder investigation
Multicluster Engine for Kubernetesmulticluster-engine/clusterlifecycle-state-metrics-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/hypershift-addon-rhel9-operatorUnder investigation
Multicluster Engine for Kubernetesmulticluster-engine/maestro-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/managedcluster-import-controller-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/multicloud-manager-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/placement-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/registration-operator-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/work-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2467815net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame

EPSS

Процентиль: 52%
0.00781
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

CVSS3: 7.5
nvd
3 месяца назад

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

CVSS3: 7.5
msrc
3 месяца назад

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

CVSS3: 7.5
debian
3 месяца назад

When processing HTTP/2 SETTINGS frames, transport will enter an infini ...

suse-cvrf
около 1 месяца назад

Security update for ignition

EPSS

Процентиль: 52%
0.00781
Низкий

7.5 High

CVSS3