Executive brief
Protocol::HTTP2 is a Perl library that implements the HTTP/2 network protocol, commonly used in web servers and HTTP clients. An attacker can exhaust server memory by repeatedly opening and closing HTTP/2 streams on a single connection. Closed streams are never removed from the connection's internal table, allowing a remote attacker to gradually consume gigabytes of RAM with ordinary-looking HTTP requests, causing service degradation or denial of service.
Technical details
Protocol::HTTP2 has a resource exhaustion vulnerability in stream state management (CVE-2026-16028). When an HTTP/2 stream transitions to the CLOSED state, the stream_state function clears the stream's data but leaves the stream entry in the connection's stream table indefinitely. An attacker can exploit this by repeatedly opening and closing streams with monotonically increasing stream identifiers; each closed stream retains approximately 920 bytes in the table despite consuming only ~19 bytes on the wire. The SETTINGS_MAX_CONCURRENT_STREAMS parameter does not prevent this attack since it only limits live streams, not accumulated closed ones. The vulnerability requires a network-reachable HTTP/2 server; a patch (version 1.14+) implements a max_closed_streams limit (default 65,535) to prevent unbounded accumulation.
Affected products
- Perl Protocol::HTTP2 before 1.14
Timeline
- 2026-09-07: disclosed
- 2026-08-29: patched: Fix committed upstream; version 1.14+ includes closed stream limit