github.com/moby/spdystream
Activity
- Latest release
- 5mo ago
- Total releases
- 6
- Cadence
- ~25 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- First release
- Jan 26, 2021
| Version | Released | |
|---|---|---|
v0.5.1
patch
|
v0.5.1
patch
|
|
v0.5.0
minor
1 CVE
CVE-2026-35469
GO-2026-4958
GHSA-pc3f-x583-g7j2
May 26, 2026
Uncontrolled resource consumption when parsing SPDY frames in github.com/moby/spdystream The SPDY/3 frame parser in spdystream does not validate attacker-controlled counts and lengths before allocating memory. A remote peer that can send SPDY frames to a service using spdystream can cause the process to allocate gigabytes of memory with a small number of malformed control frames, leading to an out-of-memory crash. Three allocation paths in the receive side are affected:
Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into attacker-controlled bytes that the parser interprets as 32-bit counts and lengths. A single crafted frame is enough to exhaust process memory. Fixed in
0.5.1
References Updated May 27, 2026 · Source: OSV.dev |
v0.5.0
minor
|
|
v0.4.0
minor
1 CVE
CVE-2026-35469
GO-2026-4958
GHSA-pc3f-x583-g7j2
May 26, 2026
Uncontrolled resource consumption when parsing SPDY frames in github.com/moby/spdystream The SPDY/3 frame parser in spdystream does not validate attacker-controlled counts and lengths before allocating memory. A remote peer that can send SPDY frames to a service using spdystream can cause the process to allocate gigabytes of memory with a small number of malformed control frames, leading to an out-of-memory crash. Three allocation paths in the receive side are affected:
Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into attacker-controlled bytes that the parser interprets as 32-bit counts and lengths. A single crafted frame is enough to exhaust process memory. Fixed in
0.5.1
References Updated May 27, 2026 · Source: OSV.dev |
v0.4.0
minor
|
|
v0.3.0
minor
1 CVE
CVE-2026-35469
GO-2026-4958
GHSA-pc3f-x583-g7j2
May 26, 2026
Uncontrolled resource consumption when parsing SPDY frames in github.com/moby/spdystream The SPDY/3 frame parser in spdystream does not validate attacker-controlled counts and lengths before allocating memory. A remote peer that can send SPDY frames to a service using spdystream can cause the process to allocate gigabytes of memory with a small number of malformed control frames, leading to an out-of-memory crash. Three allocation paths in the receive side are affected:
Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into attacker-controlled bytes that the parser interprets as 32-bit counts and lengths. A single crafted frame is enough to exhaust process memory. Fixed in
0.5.1
References Updated May 27, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (1)
|
|
v0.2.0
minor
1 CVE
CVE-2026-35469
GO-2026-4958
GHSA-pc3f-x583-g7j2
May 26, 2026
Uncontrolled resource consumption when parsing SPDY frames in github.com/moby/spdystream The SPDY/3 frame parser in spdystream does not validate attacker-controlled counts and lengths before allocating memory. A remote peer that can send SPDY frames to a service using spdystream can cause the process to allocate gigabytes of memory with a small number of malformed control frames, leading to an out-of-memory crash. Three allocation paths in the receive side are affected:
Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into attacker-controlled bytes that the parser interprets as 32-bit counts and lengths. A single crafted frame is enough to exhaust process memory. Fixed in
0.5.1
References Updated May 27, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (1)
|
|
v0.1.0
initial
1 CVE
CVE-2026-35469
GO-2026-4958
GHSA-pc3f-x583-g7j2
May 26, 2026
Uncontrolled resource consumption when parsing SPDY frames in github.com/moby/spdystream The SPDY/3 frame parser in spdystream does not validate attacker-controlled counts and lengths before allocating memory. A remote peer that can send SPDY frames to a service using spdystream can cause the process to allocate gigabytes of memory with a small number of malformed control frames, leading to an out-of-memory crash. Three allocation paths in the receive side are affected:
Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into attacker-controlled bytes that the parser interprets as 32-bit counts and lengths. A single crafted frame is enough to exhaust process memory. Fixed in
0.5.1
References Updated May 27, 2026 · Source: OSV.dev |
v0.1.0
initial
Dependencies (1)
|