Skip to content

h2 unbounded empty DATA frames

Low
seanmonstar published GHSA-q83h-524g-xf6h Aug 17, 2026

Package

cargo h2 (Rust)

Affected versions

< 0.4.16

Patched versions

0.4.16

Description

Summary

The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.

Impact

Severity: Low

If affected, this can result in unbounded memory growth and unnecessary CPU consumption, or denial of service.

To determine if vulnerable, all these things must be true:

  • You are using HTTP/2, either as a server or a client.
  • Your application does not fully drain incoming request or response bodies (for example, a proxy applying backpressure, or a client that delays reading the body).
  • The direct remote peer is malicious and intentionally sends large numbers of empty DATA frames.

Patches

We have released the following patch version(s):

  • v0.4.16

Workarounds

Besides upgrading, you can take the following actions:

  • Actively drain all incoming body streams.
  • Place a proxy in-between your h2 service and a peer that enforces empty DATA frame limits.

Credits

  • Reported-by: SCADA StrangeLove
  • Patched-by: Sean McArthur

Severity

Low

CVE ID

No known CVE

Weaknesses

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource. Learn more on MITRE.

Credits