Executive brief
h2o is a high-performance HTTP server used to deliver web content and manage network traffic. A vulnerability in its handling of the HTTP/2 protocol allows an attacker to consume excessive server memory by sending specially crafted, compressed headers and then intentionally slowing down the connection. This can lead to a denial-of-service (DoS) condition, making the server unavailable to legitimate users and disrupting business operations.
Technical details
A resource exhaustion vulnerability exists in h2o's HTTP/2 implementation due to improper bounding of decoded header state. The flaw combines HPACK decompression amplification (where small compressed headers expand into large memory structures) with Slowloris-style stream stalling, which keeps these large structures resident in memory for extended periods. An unauthenticated remote attacker can exploit this by opening multiple HTTP/2 streams and stalling them, leading to memory exhaustion and a denial-of-service. The issue is addressed in commit 9265bdd by introducing stricter limits on header state and request lengths.
Affected products
- h2o h2o Prior to commit 9265bdd
Timeline
- 2026-06-04: patched: Fix merged in commit 9265bdd
- 2026-07-17: disclosed: CVE published to NVD