-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The core vulnerability stems from improper resource management in two key areas: 1) The recv_reset function handled RST_STREAM frames without enforcing limits on pending reset streams, as shown in the fix (hyperium/h2#668) that added max_pending_accept_reset_streams checks. 2) The stream storage system (Store) allowed accumulation of closed streams due to delayed release, as described in the original issue (hyperium/hyper#2877). The high confidence for recv_reset comes from direct PR evidence, while medium confidence for Store::inner_push comes from problem description about slab growth despite stream closure.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| h2 | rust | < 0.3.17 | 0.3.17 |
Ongoing coverage of React2Shell