{"id":"CVE-2016-6580","aliases":["GHSA-h3q4-6j7f-r24c","PYSEC-2017-93"],"url":"https://o3.security/vulnerability/CVE-2016-6580","summary":"priority vulnerable to denial of service","details":"A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream, and would therefore allocate unbounded amounts of memory. Attempting to actually use a tree like this would also cause extremely high CPU usage to maintain the tree.","published":"2017-01-10T15:59:00.377Z","modified":"2026-07-08T12:06:08.970574Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"priority","fixedVersion":"1.2.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/92311"},{"type":"ADVISORY","url":"https://python-hyper.org/priority/en/latest/security/CVE-2016-6580.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:06:08.970574Z"}}