PT-2026-7868 · Unknown · Webtransport-Go

Marten-Seemann

·

Publicado

2026-02-12

·

Atualizado

2026-03-03

·

CVE-2026-21434

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions webtransport-go versions 0.3.0 through 0.9.0
Description webtransport-go’s session implementation is susceptible to excessive memory consumption. An attacker can send a WT CLOSE SESSION capsule containing an excessively large Application Error Message. The implementation does not enforce the draft-mandated 1024-byte limit on this field, allowing an attacker to send an arbitrarily large message payload that is fully read and stored in memory. This allows an attacker to consume an arbitrary amount of memory, requiring the full payload transmission to achieve the memory consumption.
Recommendations Upgrade to version 10.0.0 or later.

Exploit

Correção

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21434
GHSA-G6X7-JQ8P-6Q9Q
GO-2026-4485
SUSE-SU-2026:0757-1

Produtos afetados

Webtransport-Go