Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Link | Tags |
---|---|
https://github.com/hyperium/hyper/issues/2826 | issue tracking patch vendor advisory exploit |
https://github.com/hyperium/hyper/pull/2828 | issue tracking patch |
https://github.com/hyperium/hyper/compare/v0.14.18...v0.14.19 | patch |