← Vulnerability feed

Vulnerability record · CVE-2026-35469 · published 16 April 2026

CVE-2026-35469: Allocation without limits vulnerability

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.

8.7 CVSS 4.0 High EPSS 0.79% · top 45.6% CWE-770 · Allocation without limits Deferred
8.7CVSS 4.0 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
89References
11 Sep 2026Last modified by NVD

Description

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

References

LinkTags
https://github.com/moby/spdystream/releases/tag/v0.5.1
https://github.com/moby/spdystream/security/advisories/GHSA-pc3f-x583-g7j2
https://access.redhat.com/errata/RHSA-2026:11070
https://access.redhat.com/errata/RHSA-2026:11217
https://access.redhat.com/errata/RHSA-2026:12118
https://access.redhat.com/errata/RHSA-2026:13791
https://access.redhat.com/errata/RHSA-2026:13829
https://access.redhat.com/errata/RHSA-2026:17121
https://access.redhat.com/errata/RHSA-2026:17123
https://access.redhat.com/errata/RHSA-2026:17449
https://access.redhat.com/errata/RHSA-2026:17468
https://access.redhat.com/errata/RHSA-2026:17469
https://access.redhat.com/errata/RHSA-2026:17475
https://access.redhat.com/errata/RHSA-2026:17598
https://access.redhat.com/errata/RHSA-2026:17599
https://access.redhat.com/errata/RHSA-2026:17704
https://access.redhat.com/errata/RHSA-2026:19099
https://access.redhat.com/errata/RHSA-2026:19108
https://access.redhat.com/errata/RHSA-2026:20034
https://access.redhat.com/errata/RHSA-2026:20041
https://access.redhat.com/errata/RHSA-2026:20042
https://access.redhat.com/errata/RHSA-2026:20089
https://access.redhat.com/errata/RHSA-2026:21658
https://access.redhat.com/errata/RHSA-2026:21692
https://access.redhat.com/errata/RHSA-2026:21697
https://access.redhat.com/errata/RHSA-2026:23235
https://access.redhat.com/errata/RHSA-2026:25009
https://access.redhat.com/errata/RHSA-2026:25046
https://access.redhat.com/errata/RHSA-2026:25187
https://access.redhat.com/errata/RHSA-2026:25194
https://access.redhat.com/errata/RHSA-2026:25201
https://access.redhat.com/errata/RHSA-2026:25207
https://access.redhat.com/errata/RHSA-2026:27004
https://access.redhat.com/errata/RHSA-2026:27010
https://access.redhat.com/errata/RHSA-2026:27063
https://access.redhat.com/errata/RHSA-2026:27903
https://access.redhat.com/errata/RHSA-2026:27914
https://access.redhat.com/errata/RHSA-2026:27941
https://access.redhat.com/errata/RHSA-2026:27983
https://access.redhat.com/errata/RHSA-2026:29795

Track CVE-2026-35469 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2026-35469), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.