PT-2026-7869 · Unknown · Webtransport-Go

Marten-Seemann

·

Published

2026-02-12

·

Updated

2026-03-03

·

CVE-2026-21435

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions webtransport-go versions prior to 0.10.0
Description A malicious peer can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport session closure. Specifically, a peer can withhold QUIC flow control credit on the CONNECT stream, blocking transmission of the WT CLOSE SESSION capsule and causing the close operation to hang. The WebTransport protocol signals session termination by sending a WT CLOSE SESSION capsule on the CONNECT stream. Affected versions blocked indefinitely while waiting for sufficient QUIC flow control credit from the peer.
Recommendations Update to version 0.10.0 or later.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-21435
GHSA-PX4R-G4P3-HHQV
GO-2026-4488
SUSE-SU-2026:0757-1

Affected Products

Webtransport-Go