PT-2026-7869 · Unknown · Webtransport-Go
Marten-Seemann
·
Published
2026-02-12
·
Updated
2026-03-03
·
CVE-2026-21435
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
webtransport-go versions prior to 0.10.0
Description
A malicious peer can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport session closure. Specifically, a peer can withhold QUIC flow control credit on the CONNECT stream, blocking transmission of the WT CLOSE SESSION capsule and causing the close operation to hang. The WebTransport protocol signals session termination by sending a WT CLOSE SESSION capsule on the CONNECT stream. Affected versions blocked indefinitely while waiting for sufficient QUIC flow control credit from the peer.
Recommendations
Update to version 0.10.0 or later.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webtransport-Go