The Lab · 2026-04-16 21:22:54 · GitHub Issues
A critical memory exhaustion vulnerability in the widely used `moby/spdystream` library has been patched, forcing a mandatory update for any service relying on SPDY/3 communication. The flaw, tracked as CVE-2026-35469, resides in the library's frame parser, which fails to validate attacker-controlled counts and lengths...
The Lab · 2026-04-17 20:22:51 · GitHub Issues
A critical security flaw in the widely used `moby/spdystream` library exposes services to remote memory exhaustion attacks. The vulnerability, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled input before allocating memory. This allows a remote peer to send a sm...
The Lab · 2026-04-18 02:22:38 · GitHub Issues
A critical security vulnerability in the widely used `moby/spdystream` library exposes services to remote memory exhaustion attacks. The flaw, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled data before allocating system memory. This allows a remote peer to sen...
The Lab · 2026-04-19 10:22:38 · GitHub Issues
A critical security flaw in the widely used `moby/spdystream` library exposes services to remote memory exhaustion attacks. The vulnerability, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled counts and lengths before allocating memory. This allows a remote peer...
The Lab · 2026-04-19 11:22:34 · GitHub Issues
A critical memory exhaustion vulnerability in the widely used `moby/spdystream` library has been patched, forcing a mandatory security update for countless dependent projects. The flaw, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled counts and lengths before a...
The Lab · 2026-04-19 12:22:38 · GitHub Issues
A critical security vulnerability in the widely used `moby/spdystream` library has been patched, forcing a mandatory update for any service relying on it. The flaw, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser and allows a remote attacker to trigger uncontrolled memory allocation, potentially causing a...
The Lab · 2026-05-10 15:32:05 · GitHub Issues
A security fix for CVE-2026-35469 in OpenShift Container Manager release 2.15 has revealed the intricate challenge of patching vulnerabilities buried deep in indirect dependency trees. The target package, github.com/moby/spdystream, must be upgraded to v0.5.1 to address the vulnerability, but the fix cannot be applied ...