h2
HTTP 2.0 client & server implementation for Rust.
Activity
- Latest release
- 2w ago
- Total releases
- 87
- Cadence
- ~41 days
- Last 12 months
- 7
Reach
- Downloads
- 756.6M
- Stars
- 1.5k
Details
- License
- MIT
- First release
- Mar 09, 2017
| Version | Released | |
|---|---|---|
0.4.19
patch
|
0.4.19
patch
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.18
patch
|
0.4.18
patch
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.17
patch
|
0.4.17
patch
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.16
patch
|
0.4.16
patch
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.15
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.15
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.14
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.14
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.13
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.13
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.12
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.12
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.27
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.3.27
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.11
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.11
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.10
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.10
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.9
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.9
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.8
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.8
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.7
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.7
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.6
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.6
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.5
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.4.5
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.4
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev | ||
0.3.26
unknown
1 CVE
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev |
0.3.26
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.3
unknown
2 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.25
unknown
2 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.25
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.2
unknown
2 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.24
unknown
2 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.24
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.23
unknown
3 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.23
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.4.1
unknown
3 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.0
unknown
3 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.22
unknown
3 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.22
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.21
unknown
3 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.21
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.20
unknown
3 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.20
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.19
unknown
3 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.19
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.18
unknown
3 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.18
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.17
unknown
yanked
3 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.17
unknown
yanked
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.16
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.16
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.15
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.15
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.14
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.14
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.13
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.13
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.12
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.12
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.3.11
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.11
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.10
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.10
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.9
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.9
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.8
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.8
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.7
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.7
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.6
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.6
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.5
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.5
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.4
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.4
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.3
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.3
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.2
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.2
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.1
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.1
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.3.0
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.3.0
unknown
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
0.2.7
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.2.7
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.2.6
unknown
4 CVEs
RUSTSEC-2026-0258
GHSA-q83h-524g-xf6h
Aug 17, 2026
h2 unbounded empty DATA frames The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows. Low severity. Patched in v0.4.16. Fixed in
0.4.16
References Updated Aug 18, 2026 · Source: OSV.dev
GHSA-q6cp-qfwq-4gcv
RUSTSEC-2024-0332
Apr 05, 2024
h2 servers vulnerable to degradation of service with CONTINUATION Flood
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An attacker can send a flood of CONTINUATION frames, causing Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency. More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/. Patches available for 0.4.x and 0.3.x versions. Fixed in
0.3.26
0.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-8r5v-vm4m-4g25
RUSTSEC-2024-0003
Jan 19, 2024
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Medium
An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the generation of reset frames on the victim endpoint. By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion, resulting in Out Of Memory (OOM) and high CPU usage. This fix is corrected in hyperium/h2#737, which limits the total number of internal error resets emitted by default before the connection is closed. Fixed in
0.3.24
0.4.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-26964
RUSTSEC-2023-0034
GHSA-f8vr-r385-rh5r
Apr 14, 2023
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS) If an attacker is able to flood the network with pairs of This flaw is corrected in hyperium/h2#668, which restricts remote reset stream count by default. Fixed in
0.3.17
References Updated Nov 08, 2023 · Source: OSV.dev |
0.2.6
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|