{"id":"GHSA-q6cp-qfwq-4gcv","aliases":["RUSTSEC-2024-0332"],"url":"https://o3.security/vulnerability/GHSA-q6cp-qfwq-4gcv","summary":"h2 servers vulnerable to degradation of service with CONTINUATION Flood","details":"An attacker can send a flood of CONTINUATION frames, causing `h2` to process them indefinitely. This results in an increase in CPU usage.\n\nTokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency.\n\nMore details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/.\n\nPatches available for 0.4.x and 0.3.x versions.\n","published":"2024-04-05T15:05:32Z","modified":"2026-09-10T03:49:18.784343884Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"h2","fixedVersion":"0.3.26"},{"ecosystem":"crates.io","name":"h2","fixedVersion":"0.4.4"}],"fix":null,"references":[{"type":"PACKAGE","url":"https://github.com/hyperium/h2"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2024-0332.html"},{"type":"WEB","url":"https://seanmonstar.com/blog/hyper-http2-continuation-flood"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/421644"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:49:18.784343884Z"}}