PT-2026-33367 · Unknown · Spdystream

CVE-2026-35469

·

Published

2026-04-16

·

Updated

2026-08-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions spdystream versions prior to 0.5.1
Description The SPDY/3 frame parser fails to validate attacker-controlled counts and lengths before allocating memory. This occurs in three allocation paths: the SETTINGS frame entry count, the header count in the parseHeaderValueBlock() function, and individual header field sizes. These values are read as 32-bit integers and used directly for allocation without bounds checking. Since SPDY header blocks use zlib compression (a method of reducing data size), a small payload can decompress into large values. A remote peer can send a single crafted control frame to exhaust process memory, leading to an out-of-memory crash and denial of service.
Recommendations Update to version 0.5.1.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-82937
AZL-85605
AZL-85625
AZL-85628
AZL-85634
AZL-85637
AZL-85640
AZL-85679
AZL-85682
AZL-85685
AZL-85688
AZL-85694
CLEANSTART-2026-AH59738
CLEANSTART-2026-AY53560
CLEANSTART-2026-BE68531
CLEANSTART-2026-BS27946
CLEANSTART-2026-BX78383
CLEANSTART-2026-CL67452
CLEANSTART-2026-DG85765
CLEANSTART-2026-DK45320
CLEANSTART-2026-DN20646
CLEANSTART-2026-DN70218
CLEANSTART-2026-DT92404
CLEANSTART-2026-EH36582
CLEANSTART-2026-GB38700
CLEANSTART-2026-GQ12922
CLEANSTART-2026-GR41888
CLEANSTART-2026-GZ35045
CLEANSTART-2026-HI64288
CLEANSTART-2026-HO16255
CLEANSTART-2026-IP78312
CLEANSTART-2026-IT06487
CLEANSTART-2026-JC64695
CLEANSTART-2026-JI51299
CLEANSTART-2026-JI93588
CLEANSTART-2026-JO51351
CLEANSTART-2026-JV26120
CLEANSTART-2026-KJ85611
CLEANSTART-2026-KL41807
CLEANSTART-2026-KX80654
CLEANSTART-2026-LG16061
CLEANSTART-2026-LO51673
CLEANSTART-2026-LO55919
CLEANSTART-2026-LT10352
CLEANSTART-2026-LU21824
CLEANSTART-2026-MJ39387
CLEANSTART-2026-ML42911
CLEANSTART-2026-MY68881
CLEANSTART-2026-NT80635
CLEANSTART-2026-OD47693
CLEANSTART-2026-OH87240
CLEANSTART-2026-OO10146
CLEANSTART-2026-OX51942
CLEANSTART-2026-PU75130
CLEANSTART-2026-QO29688
CLEANSTART-2026-QT53274
CLEANSTART-2026-QX43073
CLEANSTART-2026-SA78596
CLEANSTART-2026-SK14500
CLEANSTART-2026-SM80424
CLEANSTART-2026-TH33219
CLEANSTART-2026-TO13966
CLEANSTART-2026-TT42218
CLEANSTART-2026-UI27816
CLEANSTART-2026-UJ59341
CLEANSTART-2026-UW03847
CLEANSTART-2026-UX07516
CLEANSTART-2026-UY68298
CLEANSTART-2026-VD47610
CLEANSTART-2026-VN02574
CLEANSTART-2026-VR76068
CLEANSTART-2026-VV82680
CLEANSTART-2026-WA48911
CLEANSTART-2026-WF25734
CLEANSTART-2026-WL14185
CLEANSTART-2026-WU90227
CLEANSTART-2026-WV75091
CLEANSTART-2026-WW79343
CLEANSTART-2026-WY21381
CLEANSTART-2026-WY50383
CLEANSTART-2026-XI63678
CLEANSTART-2026-XR35583
CLEANSTART-2026-XS03563
CLEANSTART-2026-XV43582
CLEANSTART-2026-YB92538
CLEANSTART-2026-YV44838
CLEANSTART-2026-YY48565
CLEANSTART-2026-YZ69292
CLEANSTART-2026-YZ90223
CLEANSTART-2026-ZN45188
CVE-2026-35469
GHSA-PC3F-X583-G7J2
GO-2026-4958
OESA-2026-2162
OESA-2026-3564
OPENSUSE-SU-2026:11107-1
OPENSUSE-SU-2026:11305-1
OPENSUSE-SU-2026:11307-1
OPENSUSE-SU-2026:11514-1
OPENSUSE-SU-2026:21213-1
OPENSUSE-SU-2026:21483-1
OPENSUSE-SU-2026:21590-1
RHSA-2026:34755
RHSA-2026:36796
RHSA-2026:41019
RHSA-2026:51422
SUSE-SU-2026:22800-1
SUSE-SU-2026:22892-1
SUSE-SU-2026:2315-1
SUSE-SU-2026:2322-1
SUSE-SU-2026:2325-1
SUSE-SU-2026:2339-1
SUSE-SU-2026:2340-1
SUSE-SU-2026:2342-1
SUSE-SU-2026:2343-1
SUSE-SU-2026:2344-1
SUSE-SU-2026:2345-1
SUSE-SU-2026:2460-1
SUSE-SU-2026:2783-1
SUSE-SU-2026:2804-1
SUSE-SU-2026:3203-1
SUSE-SU-2026:3450-1
SUSE-SU-2026:3504-1
SUSE-SU-2026:3630-1

Affected Products

Spdystream