PT-2026-7868 · Unknown · Webtransport-Go

Marten-Seemann

·

Published

2026-02-12

·

Updated

2026-03-03

·

CVE-2026-21434

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions webtransport-go versions 0.3.0 through 0.9.0
Description webtransport-go’s session implementation is susceptible to excessive memory consumption. An attacker can send a WT CLOSE SESSION capsule containing an excessively large Application Error Message. The implementation does not enforce the draft-mandated 1024-byte limit on this field, allowing an attacker to send an arbitrarily large message payload that is fully read and stored in memory. This allows an attacker to consume an arbitrary amount of memory, requiring the full payload transmission to achieve the memory consumption.
Recommendations Upgrade to version 10.0.0 or later.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-21434
GHSA-G6X7-JQ8P-6Q9Q
GO-2026-4485
SUSE-SU-2026:0757-1

Affected Products

Webtransport-Go