RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0258

h2 unbounded empty DATA frames

Reported
Issued
Package
h2 (crates.io)
Type
Vulnerability
Categories
Keywords
#http #http2 #h2
Aliases
References
Patched
  • >=0.4.16

Description

The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.

Low severity.

Patched in v0.4.16.

Advisory available under CC0-1.0 license.