Project

General

Profile

Actions

Security #8555

closed
OT PA

http2: excessive memory alloc with decompression bomb (7.0.x backport)

Security #8555: http2: excessive memory alloc with decompression bomb (7.0.x backport)

Added by OISF Ticketbot 22 days ago. Updated about 11 hours ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:

16c689cbec9d424392c5547c959ad0b2d8bb8a60
b468bd631c5b9ddc153404b2b23abf48daf25fee
5c6af4419b82ce5a1f7b6e19f0a7b5b907997f78

Severity:
HIGH
Disclosure Date:
07/03/2026

JI Updated by Jason Ish 22 days ago Actions #1

  • Disclosure Date set to 07/03/2026
  • GHSA set to GHSA-45p7-j5wm-8wrx

JI Updated by Jason Ish 21 days ago Actions #2

  • Severity set to HIGH

JI Updated by Jason Ish 20 days ago Actions #3

  • CVE set to 2026-46387

SB Updated by Shivani Bhardwaj 20 days ago Actions #4

  • Subject changed from http2: protection against compression bombs (7.0.x backport) to http2: excessive memory alloc with decompression bomb (7.0.x backport)

PA Updated by Philippe Antoine 16 days ago Actions #5

  • Status changed from Assigned to In Review

Gitlab MR Staging v3

VJ Updated by Victor Julien 15 days ago Actions #6

  • Status changed from In Review to Resolved

VJ Updated by Victor Julien 15 days ago Actions #7

  • Status changed from Resolved to Closed

JI Updated by Jason Ish 15 days ago Actions #8

  • Git IDs updated (diff)

JI Updated by Jason Ish about 11 hours ago Actions #9

  • Private changed from Yes to No
Actions

Also available in: PDF Atom