PT-2026-60605 · H2O · H2O

CVE-2026-54340

·

Published

2026-07-16

·

Updated

2026-08-05

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions h2o versions prior to commit 9265bdd
Description An HTTP/2 state amplification issue exists that combines HPACK decompression amplification with Slowloris-style stream stalling. This allows amplified decoded header state to be retained by stalled HTTP/2 streams. Depending on the configuration, additional limits are required to bound the decoded header state to prevent this attack.
Recommendations Update to the version containing commit 9265bdd.

Exploit

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54340
GHSA-QCRR-WRHC-PGQ9

Affected Products

H2O