h2o是H2O公司开源的一款新一代HTTP服务器。 H2O 6b5370d之前版本存在资源管理错误漏洞,该漏洞源于调用alloca时超过默认栈大小,当处理静态文件时在栈上构建文件路径,可能导致拒绝服务攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44436 | 7.5 HIGH | Quicly is vulnerable to connection state corruption |
| CVE-2026-44435 | 7.5 HIGH | Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data e |
| CVE-2026-54340 | 7.5 HIGH | h2o has HTTP/2 state amplification |
| CVE-2026-44452 | 5.9 MEDIUM | h2o is vulnerable to heap overrun |
| CVE-2026-44433 | 5.3 MEDIUM | Quicly is vulnerable to memory exhaustion |
| CVE-2026-44434 | 5.3 MEDIUM | Quicly is vulnerable to stateless reset injection |
No comments yet