The Lab · 2026-04-16 21:22:54 · GitHub Issues
A critical memory exhaustion vulnerability in the widely used `moby/spdystream` library has been patched, forcing a mandatory update for any service relying on SPDY/3 communication. The flaw, tracked as CVE-2026-35469, resides in the library's frame parser, which fails to validate attacker-controlled counts and lengths...
The Lab · 2026-04-19 10:22:38 · GitHub Issues
A critical security flaw in the widely used `moby/spdystream` library exposes services to remote memory exhaustion attacks. The vulnerability, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled counts and lengths before allocating memory. This allows a remote peer...
The Lab · 2026-04-19 11:22:34 · GitHub Issues
A critical memory exhaustion vulnerability in the widely used `moby/spdystream` library has been patched, forcing a mandatory security update for countless dependent projects. The flaw, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled counts and lengths before a...
The Lab · 2026-05-12 03:48:23 · GitHub Issues
A critical security vulnerability has been identified in golang.org/x/net, the widely-used Go standard library module, triggering an urgent dependency update across the ecosystem. The flaw, tracked as CVE-2026-33814 (GO-2026-4918), resides in the HTTP/2 transport implementation within net/http/internal/http2 and can ca...