PT-2026-7868 · Unknown · Webtransport-Go
Marten-Seemann
·
Published
2026-02-12
·
Updated
2026-03-03
·
CVE-2026-21434
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
webtransport-go versions 0.3.0 through 0.9.0
Description
webtransport-go’s session implementation is susceptible to excessive memory consumption. An attacker can send a
WT CLOSE SESSION capsule containing an excessively large Application Error Message. The implementation does not enforce the draft-mandated 1024-byte limit on this field, allowing an attacker to send an arbitrarily large message payload that is fully read and stored in memory. This allows an attacker to consume an arbitrary amount of memory, requiring the full payload transmission to achieve the memory consumption.Recommendations
Upgrade to version 10.0.0 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webtransport-Go