VORANT. Threat Intelligence Sign in Get the full feed

HTTP/2 flow-control flaw enables server DoS

medium vulnerability technologytelecommunications

A HTTP/2 flow-control abuse technique lets unauthenticated attackers exhaust server memory in Apache Traffic Server, Citrix NetScaler, F5 BIG-IP, and Meta implementations.

CERT/CC disclosed a denial-of-service vulnerability affecting multiple HTTP/2 server implementations that fail to properly bound memory when clients stall flow control. By setting SETTINGS_INITIAL_WINDOW_SIZE to zero or withholding WINDOW_UPDATE frames while opening many concurrent streams requesting large resources, a remote unauthenticated attacker can force servers to buffer large amounts of unsendable response data, leading to memory exhaustion, swap thrashing, and potential crashes or worker/connection starvation.

Confirmed affected implementations include Apache Traffic Server (CVE-2026-59173, fixed in 9.2.14/10.1.3 via hard enforcement of stream limits with REFUSED_STREAM), Citrix NetScaler ADC/Gateway when HTTP/2 is enabled, F5 BIG-IP (CVE-2026-59762), and Meta (CVE-2026-44909). Citrix requires both an upgrade and manual configuration of the new Http2SmallWndTimeout parameter for non-Strict HTTP Profiles to fully remediate. Numerous other vendors (Cloudflare, Fastly, GitHub, BIND, HAProxy, nghttp2, Tempesta, and others) reported they are not affected due to conservative buffer or timeout limits, while a large number of vendors have not yet issued statements.

The issue is conceptually related to prior HTTP/2 DoS classes such as Data Dribble (CVE-2019-9511). The IETF HTTP Working Group noted the underlying RFC 9113 specification is not at fault, placing responsibility on individual implementations that fail to enforce memory ceilings, concurrent stream limits, and stalled-connection timeouts. Organizations running affected HTTP/2 servers should apply vendor patches and configure resource limits to mitigate exposure.

Mentioned in this report

Vulnerabilities CVE-2026-44909CVE-2026-59173CVE-2026-59762

Source reporting: https://kb.cert.org/vuls/id/885548

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free