Allocation of Resources Without Limits or Throttling in spdystream - CVE-2026-35469

 

Allocation of Resources Without Limits or Throttling in spdystream - CVE-2026-35469

Published: July 20, 2026


Vulnerability identifier: #VU138768
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35469
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

spdystream
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
openEuler
Fedora
MongoDB Enterprise Advanced with IBM
IBM Business Automation Workflow
containerd
containerd-ctr
containerd-devel
kubernetes
kubernetes-client
kubernetes-help
kubernetes-kubeadm
kubernetes-kubelet
kubernetes-master
kubernetes-node
kubernetes1.33
kubernetes1.34
kubernetes1.35
microshift (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat build of MicroShift

How to mitigate CVE-2026-35469

Install updates from vendor's website.

spdystream - update to 0.5.1
MongoDB Enterprise Advanced with IBM - update to 1.9.1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
containerd - update to 1.6.22-30
containerd - update to 1.7.29-16.113.1
containerd-ctr - update to 1.7.29-16.113.1
containerd-devel - update to 1.7.29-16.113.1
kubernetes - update to 1.20.2-30
kubernetes-client - update to 1.20.2-30
kubernetes-help - update to 1.20.2-30
kubernetes-kubeadm - update to 1.20.2-30
kubernetes-kubelet - update to 1.20.2-30
kubernetes-master - update to 1.20.2-30
kubernetes-node - update to 1.20.2-30
kubernetes1.33 - addressed in versions 1.33.13-1.fc43, 1.33.13-1.fc44, 1.33.13-1.fc45
kubernetes1.34 - addressed in versions 1.34.9-1.fc43, 1.34.9-1.fc44, 1.34.9-1.fc45
kubernetes1.35 - addressed in versions 1.35.6-1.fc43, 1.35.6-1.fc44, 1.35.6-1.fc45
containerd - update to 2.3.2-1.fc45
Red Hat OpenShift Container Platform - addressed in versions 4.12.93, 4.12.94, 4.13.69, 4.14.67, 4.15.65, 4.16.64, 4.16.66, 4.17.55, 4.17.56, 4.18.46, 4.18.48, 4.19.34, 4.19.35, 4.19.36, 4.19.37, 4.19.38, 4.20.27, 4.20.28, 4.20.29, 4.21.20, 4.21.22, 4.21.23, 4.21.24, 4.21.26, 4.22.1, 4.22.2, 4.22.3, 4.22.4
Red Hat build of MicroShift - update to 4.19.42
microshift (Red Hat package) - update to 4.19.42-202608062155.p0.g46c9d67.assembly.4.19.42.el9

External References

Related Security Bulletins