HTTP/2 State Amplification Vulnerability in H2O Server by H2O
CVE-2026-54340
7.5HIGH
What is CVE-2026-54340?
An HTTP/2 state amplification vulnerability exists in the H2O web server, where HPACK decompression can be exploited in conjunction with Slowloris-style stream stalling. This issue allows for potential retention of amplified decoded header state by stalled streams, requiring additional configuration limits to mitigate risks. The vulnerability has been addressed in the latest updates. It is crucial for users of H2O Server to ensure they are running the patched version to safeguard against these types of amplification attacks.
Affected Version(s)
h2o < 9265bdd
