h2o是H2O公司开源的一款新一代HTTP服务器。 h2o 9265bdd之前版本存在资源管理错误漏洞,该漏洞源于HTTP/2状态放大问题,结合HPACK解压放大与Slowloris-style流停滞,导致解码后的标头状态被停滞的HTTP/2流保留,攻击者可通过网络利用此问题造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44436 | 7.5 HIGH | Quicly is vulnerable to connection state corruption |
| CVE-2026-44435 | 7.5 HIGH | Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data e |
| CVE-2026-44453 | 7.5 HIGH | h2o is vulnerable to musl libc stack overflow |
| CVE-2026-44452 | 5.9 MEDIUM | h2o is vulnerable to heap overrun |
| CVE-2026-44433 | 5.3 MEDIUM | Quicly is vulnerable to memory exhaustion |
| CVE-2026-44434 | 5.3 MEDIUM | Quicly is vulnerable to stateless reset injection |
No comments yet