Project

General

Profile

Actions

Security #8554

closed
OT PA

http2: excessive memory alloc with decompression bomb (8.0.x backport)

Security #8554: http2: excessive memory alloc with decompression bomb (8.0.x backport)

Added by OISF Ticketbot 22 days ago. Updated about 7 hours ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:

20104d09788b606b1de1923286d463a07ad47e6d
69107199d6fbff979bad2174cd3a904ab8951bd6

Severity:
HIGH
Disclosure Date:
07/03/2026

JI Updated by Jason Ish 22 days ago Actions #1

  • Disclosure Date set to 07/03/2026
  • GHSA set to GHSA-45p7-j5wm-8wrx

JI Updated by Jason Ish 20 days ago Actions #2

  • Severity set to HIGH

JI Updated by Jason Ish 20 days ago Actions #3

  • CVE set to 2026-46387

JI Updated by Jason Ish 20 days ago Actions #4

  • Status changed from Assigned to In Review

SB Updated by Shivani Bhardwaj 16 days ago Actions #5

  • Subject changed from http2: protection against compression bombs (8.0.x backport) to http2: excessive memory alloc with decompression bomb (8.0.x backport)

SB Updated by Shivani Bhardwaj 15 days ago Actions #6

  • Status changed from In Review to Resolved

VJ Updated by Victor Julien 15 days ago Actions #7

  • Status changed from Resolved to Closed

JI Updated by Jason Ish 15 days ago Actions #8

  • Git IDs updated (diff)

JI Updated by Jason Ish about 7 hours ago Actions #9

  • Private changed from Yes to No
Actions

Also available in: PDF Atom