PT-2026-71895 · Rocky Linux · Rocky Linux

CVE-2026-56853

·

Published

2026-08-13

·

Updated

2026-09-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. During this process, the ReadHeaderTimeout is not applied, which may lead to resource exhaustion.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:60304
ALSA-2026:60305
ALSA-2026:60306
ALSA-2026:62406
ALSA-2026:62407
ALSA-2026:62578
ALSA-2026:62631
ALSA-2026:63022
ALSA-2026:63119
ALSA-2026:63124
ALSA-2026:63332
ALSA-2026:64777
ALSA-2026:64818
ALSA-2026:65116
ALSA-2026:65117
ALSA-2026:66016
AZL-96644
AZL-96680
AZL-98613
BIT-GOLANG-2026-56853
CVE-2026-56853
GO-2026-6089
OPENSUSE-SU-2026:11516-1
OPENSUSE-SU-2026:11517-1
OPENSUSE-SU-2026:11536-1
OPENSUSE-SU-2026:11727-1
OPENSUSE-SU-2026:21592-1
OPENSUSE-SU-2026:21593-1
OPENSUSE-SU-2026:21696-1
OPENSUSE-SU-2026:21705-1
OPENSUSE-SU-2026:21761-1
RHSA-2026:64777
RHSA-2026:64786
RHSA-2026:64818
RHSA-2026:65116
RHSA-2026:65117
RHSA-2026:65153
RHSA-2026:65335
RHSA-2026:65336
RHSA-2026:65359
RHSA-2026:65534
RHSA-2026:65880
RHSA-2026:65886
RHSA-2026:65895
RHSA-2026:65918
RHSA-2026:66016
RHSA-2026:66327
RHSA-2026:66459
SUSE-SU-2026:23300-1
SUSE-SU-2026:23301-1
SUSE-SU-2026:3640-1
SUSE-SU-2026:3641-1
SUSE-SU-2026:3799-1
SUSE-SU-2026:3800-1
SUSE-SU-2026:3815-1
SUSE-SU-2026:3816-1
SUSE-SU-2026:3830-1

Affected Products

Rocky Linux