Junglewise Threat Intelligence

CVE-2026-54340: h2o HTTP/2 state amplification resource exhaustion

CVE-2026-54340 · Severity: high · CVSS 7.5 · Published 2026-07-17

Vendors: H2o.

Executive brief

h2o is a high-performance HTTP server used to deliver web content and manage network traffic. A vulnerability in its handling of the HTTP/2 protocol allows an attacker to consume excessive server memory by sending specially crafted, compressed headers and then intentionally slowing down the connection. This can lead to a denial-of-service (DoS) condition, making the server unavailable to legitimate users and disrupting business operations.

Technical details

A resource exhaustion vulnerability exists in h2o's HTTP/2 implementation due to improper bounding of decoded header state. The flaw combines HPACK decompression amplification (where small compressed headers expand into large memory structures) with Slowloris-style stream stalling, which keeps these large structures resident in memory for extended periods. An unauthenticated remote attacker can exploit this by opening multiple HTTP/2 streams and stalling them, leading to memory exhaustion and a denial-of-service. The issue is addressed in commit 9265bdd by introducing stricter limits on header state and request lengths.

Affected products

  • h2o h2o Prior to commit 9265bdd

Timeline

  • 2026-06-04: patched: Fix merged in commit 9265bdd
  • 2026-07-17: disclosed: CVE published to NVD

References