An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HHyper H2
APPHyper0.2.4Hyper
APPHyper0.13.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
References
Related vulnerabilities
CVE-2020-35863CRITICAL9.8PL ✓same product
HTTP request smuggling i RCE w bibliotece hyper dla Rust
CVE-2022-31394HIGH7.5same product
Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 th...
CVE-2021-32714MEDIUM5.9same product
hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a fla...
CVE-2021-21299MEDIUM4.8same product
hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0....
CVE-2016-10932MEDIUM4.8same product
An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-midd...