🛡️ CVE-2026-35469 — spdystream

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-770 NVD
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

SpdyStream: DOS on CRI

The SPDY/3 frame parser in spdystream does not validate

attacker-controlled counts and lengths before allocating memory. A

remote peer that can send SPDY frames to a service using spdystream can

cause the process to allocate gigabytes of memory with a small number of

malformed control frames, leading to an out-of-memory crash.

 

Three allocation paths in the receive side are affected:

1. SETTINGS entry count -- The SETTINGS frame reader reads a 32-bit

numSettings from the payload and allocates a slice of that size

without checking it against the declared frame length. An attacker

can set numSettings to a value far exceeding the actual payload,

triggering a large allocation before any setting data is read.

 

2. Header count -- parseHeaderValueBlock reads a 32-bit

numHeaders from the decompressed header block and allocates an

http.Header map of that size with no upper bound.

 

3. Header field size -- Individual header name and value lengths are

read as 32-bit integers and used directly as allocation sizes with

no validation.

 

Because SPDY header blocks are zlib-compressed, a small on-the-wire

payload can decompress into attacker-controlled bytes that the parser

interprets as 32-bit counts and lengths. A single crafted frame is

enough to exhaust process memory.

Impact

 Any program that accepts SPDY connections using spdystream -- directly

or through a dependent library -- is affected. A remote peer that can

send SPDY frames to the service can crash the process with a single

crafted SPDY control frame, causing denial of service.

Affected versions

 github.com/moby/spdystream <= v0.5.0

Fix

 v0.5.1 addresses the receive-side allocation bugs and adds related

hardening:

 

Core fixes:

 

  • SETTINGS entry-count validation -- The SETTINGS frame reader now

checks that numSettings is consistent with the declared frame

length (numSettings <= (length-4)/8) before allocating.

 

  • Header count limit -- parseHeaderValueBlock enforces a maximum

number of headers per frame (default: 1000).

 

  • Header field size limit -- Individual header name and value

lengths are checked against a per-field size limit (default: 1 MiB)

before allocation.

 

  • Connection closure on protocol error -- The connection read loop

now closes the underlying net.Conn when it encounters an

InvalidControlFrame error, preventing further exploitation on the

same connection.

 

Additional hardening:

 

  • Write-side bounds checks -- All frame write methods now verify

that payloads fit within the 24-bit length field, preventing the

library from producing invalid frames.

 

Configurable limits:

 

  • Callers can adjust the defaults using NewConnectionWithOptions or

the lower-level spdy.NewFramerWithOptions with functional options:

WithMaxControlFramePayloadSize, WithMaxHeaderFieldSize, and

WithMaxHeaderCount.

 

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Weakness class

CVE-2026-35469 is classified as CWE-770: Allocation of Resources Without Limits. Resources are allocated on request with no cap, so a client can exhaust them.

Affected software

CVE-2026-35469 is recorded against 2 packages.

  • github.com/moby/spdystream
  • unknown

Timeline and source

Published on 16 April 2026 and last revised on 8 June 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
github.com (Web)

CVE-2026-35469 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE CWE-770
Public Exploit ✅ No
Source NVD
Published 2026-04-16
Updated 2026-08-12
Modified 2026-06-08

Affected Packages

Software From version Fixed in
github.com/moby/spdystream
unknown

Similar Threats

Site Security Check

Is spdystream part of your stack?

CVE-2026-35469 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.