Bug 2506531 (CVE-2026-44909) - CVE-2026-44909 proxygen: Proxygen: Denial of Service via HTTP/2 flow-control manipulation
Summary: CVE-2026-44909 proxygen: Proxygen: Denial of Service via HTTP/2 flow-control ...
Keywords:
Status: NEW
Alias: CVE-2026-44909
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2509187
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-23 17:02 UTC by OSIDB Bzimport
Modified: 2026-07-30 07:46 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-23 17:02:12 UTC
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large resources while preventing the server from transmitting responses, an attacker could induce unbounded memory growth leading to service degradation, resource exhaustion, or denial of service. Versions v2017.01.16.00 through v2026.07.20.00 are affected.


Note You need to log in before you can comment on or make changes to this bug.