Allocation of Resources Without Limits or Throttling in spdystream - CVE-2026-35469
Published: July 20, 2026
Vulnerability identifier: #VU138768
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35469
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
spdystream
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
openEuler
Fedora
MongoDB Enterprise Advanced with IBM
IBM Business Automation Workflow
containerd
containerd-ctr
containerd-devel
kubernetes
kubernetes-client
kubernetes-help
kubernetes-kubeadm
kubernetes-kubelet
kubernetes-master
kubernetes-node
kubernetes1.33
kubernetes1.34
kubernetes1.35
microshift (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat build of MicroShift
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
openEuler
Fedora
MongoDB Enterprise Advanced with IBM
IBM Business Automation Workflow
containerd
containerd-ctr
containerd-devel
kubernetes
kubernetes-client
kubernetes-help
kubernetes-kubeadm
kubernetes-kubelet
kubernetes-master
kubernetes-node
kubernetes1.33
kubernetes1.34
kubernetes1.35
microshift (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat build of MicroShift
How to mitigate CVE-2026-35469
Install updates from vendor's website.
spdystream - update to 0.5.1
MongoDB Enterprise Advanced with IBM - update to 1.9.1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
containerd - update to 1.6.22-30
containerd - update to 1.7.29-16.113.1
containerd-ctr - update to 1.7.29-16.113.1
containerd-devel - update to 1.7.29-16.113.1
kubernetes - update to 1.20.2-30
kubernetes-client - update to 1.20.2-30
kubernetes-help - update to 1.20.2-30
kubernetes-kubeadm - update to 1.20.2-30
kubernetes-kubelet - update to 1.20.2-30
kubernetes-master - update to 1.20.2-30
kubernetes-node - update to 1.20.2-30
kubernetes1.33 - addressed in versions 1.33.13-1.fc43, 1.33.13-1.fc44, 1.33.13-1.fc45
kubernetes1.34 - addressed in versions 1.34.9-1.fc43, 1.34.9-1.fc44, 1.34.9-1.fc45
kubernetes1.35 - addressed in versions 1.35.6-1.fc43, 1.35.6-1.fc44, 1.35.6-1.fc45
containerd - update to 2.3.2-1.fc45
Red Hat OpenShift Container Platform - addressed in versions 4.12.93, 4.12.94, 4.13.69, 4.14.67, 4.15.65, 4.16.64, 4.16.66, 4.17.55, 4.17.56, 4.18.46, 4.18.48, 4.19.34, 4.19.35, 4.19.36, 4.19.37, 4.19.38, 4.20.27, 4.20.28, 4.20.29, 4.21.20, 4.21.22, 4.21.23, 4.21.24, 4.21.26, 4.22.1, 4.22.2, 4.22.3, 4.22.4
Red Hat build of MicroShift - update to 4.19.42
microshift (Red Hat package) - update to 4.19.42-202608062155.p0.g46c9d67.assembly.4.19.42.el9
MongoDB Enterprise Advanced with IBM - update to 1.9.1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
containerd - update to 1.6.22-30
containerd - update to 1.7.29-16.113.1
containerd-ctr - update to 1.7.29-16.113.1
containerd-devel - update to 1.7.29-16.113.1
kubernetes - update to 1.20.2-30
kubernetes-client - update to 1.20.2-30
kubernetes-help - update to 1.20.2-30
kubernetes-kubeadm - update to 1.20.2-30
kubernetes-kubelet - update to 1.20.2-30
kubernetes-master - update to 1.20.2-30
kubernetes-node - update to 1.20.2-30
kubernetes1.33 - addressed in versions 1.33.13-1.fc43, 1.33.13-1.fc44, 1.33.13-1.fc45
kubernetes1.34 - addressed in versions 1.34.9-1.fc43, 1.34.9-1.fc44, 1.34.9-1.fc45
kubernetes1.35 - addressed in versions 1.35.6-1.fc43, 1.35.6-1.fc44, 1.35.6-1.fc45
containerd - update to 2.3.2-1.fc45
Red Hat OpenShift Container Platform - addressed in versions 4.12.93, 4.12.94, 4.13.69, 4.14.67, 4.15.65, 4.16.64, 4.16.66, 4.17.55, 4.17.56, 4.18.46, 4.18.48, 4.19.34, 4.19.35, 4.19.36, 4.19.37, 4.19.38, 4.20.27, 4.20.28, 4.20.29, 4.21.20, 4.21.22, 4.21.23, 4.21.24, 4.21.26, 4.22.1, 4.22.2, 4.22.3, 4.22.4
Red Hat build of MicroShift - update to 4.19.42
microshift (Red Hat package) - update to 4.19.42-202608062155.p0.g46c9d67.assembly.4.19.42.el9
External References
- https://github.com/moby/spdystream/releases/tag/v0.5.1
- https://github.com/moby/spdystream/security/advisories/GHSA-pc3f-x583-g7j2
- https://access.redhat.com/errata/RHSA-2026:11070
- https://access.redhat.com/errata/RHSA-2026:11217
- https://access.redhat.com/errata/RHSA-2026:12118
- https://access.redhat.com/errata/RHSA-2026:13791
- https://access.redhat.com/errata/RHSA-2026:13829
- https://access.redhat.com/errata/RHSA-2026:17121
- https://access.redhat.com/errata/RHSA-2026:17123
- https://access.redhat.com/errata/RHSA-2026:17449
- https://access.redhat.com/errata/RHSA-2026:17468
- https://access.redhat.com/errata/RHSA-2026:17469
- https://access.redhat.com/errata/RHSA-2026:17475
- https://access.redhat.com/errata/RHSA-2026:17598
- https://access.redhat.com/errata/RHSA-2026:17599
- https://access.redhat.com/errata/RHSA-2026:17704
- https://access.redhat.com/errata/RHSA-2026:19099
- https://access.redhat.com/errata/RHSA-2026:19108
- https://access.redhat.com/errata/RHSA-2026:20034
- https://access.redhat.com/errata/RHSA-2026:20041
- https://access.redhat.com/errata/RHSA-2026:20042
- https://access.redhat.com/errata/RHSA-2026:20089
- https://access.redhat.com/errata/RHSA-2026:21658
- https://access.redhat.com/errata/RHSA-2026:21692
- https://access.redhat.com/errata/RHSA-2026:21697
- https://access.redhat.com/errata/RHSA-2026:23235
- https://access.redhat.com/errata/RHSA-2026:25009
- https://access.redhat.com/errata/RHSA-2026:25046
- https://access.redhat.com/errata/RHSA-2026:25187
- https://access.redhat.com/errata/RHSA-2026:25194
- https://access.redhat.com/errata/RHSA-2026:25201
- https://access.redhat.com/errata/RHSA-2026:25207
- https://access.redhat.com/errata/RHSA-2026:27004
- https://access.redhat.com/errata/RHSA-2026:27010
- https://access.redhat.com/errata/RHSA-2026:27063
- https://access.redhat.com/errata/RHSA-2026:27903
- https://access.redhat.com/errata/RHSA-2026:27914
- https://access.redhat.com/errata/RHSA-2026:27941
- https://access.redhat.com/errata/RHSA-2026:27983
- https://access.redhat.com/errata/RHSA-2026:29795
- https://access.redhat.com/errata/RHSA-2026:29801
- https://access.redhat.com/errata/RHSA-2026:29835
- https://access.redhat.com/errata/RHSA-2026:29857
- https://access.redhat.com/errata/RHSA-2026:29858
- https://access.redhat.com/errata/RHSA-2026:29865
- https://access.redhat.com/errata/RHSA-2026:33071
- https://access.redhat.com/errata/RHSA-2026:33078
- https://access.redhat.com/errata/RHSA-2026:34050
- https://access.redhat.com/errata/RHSA-2026:34099
- https://access.redhat.com/errata/RHSA-2026:34100
- https://access.redhat.com/errata/RHSA-2026:34755
- https://access.redhat.com/errata/RHSA-2026:34766
- https://access.redhat.com/errata/RHSA-2026:34769
- https://access.redhat.com/errata/RHSA-2026:34791
- https://access.redhat.com/errata/RHSA-2026:34794
- https://access.redhat.com/errata/RHSA-2026:36162
- https://access.redhat.com/errata/RHSA-2026:36621
- https://access.redhat.com/errata/RHSA-2026:36796
- https://access.redhat.com/errata/RHSA-2026:37187
- https://access.redhat.com/errata/RHSA-2026:37193
- https://access.redhat.com/errata/RHSA-2026:37387
- https://access.redhat.com/errata/RHSA-2026:37580
- https://access.redhat.com/errata/RHSA-2026:37581
- https://access.redhat.com/errata/RHSA-2026:37629
- https://access.redhat.com/errata/RHSA-2026:41019
- https://access.redhat.com/security/cve/CVE-2026-35469
- https://bugzilla.redhat.com/show_bug.cgi?id=2457729
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35469.json
Related Security Bulletins
- Allocation of resources without limits or throttling in spdystream
- Fedora 45 update for kubernetes1.33
- Fedora 45 update for kubernetes1.34
- Fedora 45 update for kubernetes1.35
- Fedora 44 update for kubernetes1.34
- Fedora 44 update for kubernetes1.33
- Fedora 43 update for kubernetes1.33
- Fedora 43 update for kubernetes1.34
- Fedora 44 update for kubernetes1.35
- Fedora 43 update for kubernetes1.35
- Fedora 45 update for containerd
- openEuler update for kubernetes
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.22
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.16
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.22
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.21
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.20
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.20
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.12
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.21
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.20
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.18
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- SUSE update for containerd
- Allocation of Resources Without Limits or Throttling in Red Hat OpenShift Container Platform 4.17
- Allocation of Resources Without Limits or Throttling in Red Hat build of MicroShift 4.19 packages
- Multiple vulnerabilities in IBM Business Automation Workflow
- openEuler update for containerd
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21
- MongoDB Enterprise Advanced with IBM update for spdystream