{"id":"RUSTSEC-2026-0258","summary":"h2 unbounded empty DATA frames","details":"The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit.\nIf streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.\n\nLow severity.\n\nPatched in v0.4.16.","aliases":["GHSA-q83h-524g-xf6h"],"modified":"2026-08-18T08:30:03.400272048Z","published":"2026-08-17T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/h2"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0258.html"},{"type":"ADVISORY","url":"https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h"}],"affected":[{"package":{"name":"h2","ecosystem":"crates.io","purl":"pkg:cargo/h2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"},{"fixed":"0.4.16"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"arch":[],"os":[],"functions":[]}},"database_specific":{"categories":["denial-of-service"],"cvss":null,"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0258.json"}}],"schema_version":"1.9.0"}