PT-2026-7868 · Unknown · Webtransport-Go
Marten-Seemann
·
Publicado
2026-02-12
·
Atualizado
2026-03-03
·
CVE-2026-21434
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
webtransport-go versions 0.3.0 through 0.9.0
Description
webtransport-go’s session implementation is susceptible to excessive memory consumption. An attacker can send a
WT CLOSE SESSION capsule containing an excessively large Application Error Message. The implementation does not enforce the draft-mandated 1024-byte limit on this field, allowing an attacker to send an arbitrarily large message payload that is fully read and stored in memory. This allows an attacker to consume an arbitrary amount of memory, requiring the full payload transmission to achieve the memory consumption.Recommendations
Upgrade to version 10.0.0 or later.
Exploit
Correção
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Webtransport-Go