{"id":"GHSA-q6cp-qfwq-4gcv","summary":"h2 servers vulnerable to degradation of service with CONTINUATION Flood","details":"An attacker can send a flood of CONTINUATION frames, causing `h2` to process them indefinitely. This results in an increase in CPU usage.\n\nTokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency.\n\nMore details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/.\n\nPatches available for 0.4.x and 0.3.x versions.\n","aliases":["RUSTSEC-2024-0332"],"modified":"2026-09-10T03:49:18.784343884Z","published":"2024-04-05T15:05:32Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-05T15:05:32Z","nvd_published_at":null,"cwe_ids":["CWE-400","CWE-770"]},"references":[{"type":"PACKAGE","url":"https://github.com/hyperium/h2"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2024-0332.html"},{"type":"WEB","url":"https://seanmonstar.com/blog/hyper-http2-continuation-flood"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/421644"}],"affected":[{"package":{"name":"h2","ecosystem":"crates.io","purl":"pkg:cargo/h2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.26"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json"}},{"package":{"name":"h2","ecosystem":"crates.io","purl":"pkg:cargo/h2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.4.0"},{"fixed":"0.4.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-q6cp-qfwq-4gcv/GHSA-q6cp-qfwq-4gcv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}