ASP.NET Kestrel stream flow control issue causing a leak. A malicious QUIC client, that fires off many unidirectional streams with closed writing sides. This will bypass the HTTP/3 stream limit and Kestrel cannot keep up with stream processing. This may result in Denial of Service.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-38178