{"schema_version":"1.7.5","id":"CVE-2023-26964","published":"2023-04-11T00:00:00Z","modified":"2026-07-16T10:14:29.213981065Z","aliases":["GHSA-f8vr-r385-rh5r","RUSTSEC-2023-0034"],"related":["SUSE-SU-2023:2603-1","SUSE-SU-2025:02809-1","SUSE-SU-2025:02810-1","SUSE-SU-2025:02811-1","SUSE-SU-2026:3022-1","openSUSE-SU-2024:0294-1","openSUSE-SU-2024:12859-1","openSUSE-SU-2024:12861-1","openSUSE-SU-2024:12862-1","openSUSE-SU-2024:12863-1","openSUSE-SU-2024:12864-1","openSUSE-SU-2024:12866-1","openSUSE-SU-2024:12960-1","openSUSE-SU-2024:12973-1","openSUSE-SU-2024:13106-1"],"details":"An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hyperium/h2","events":[{"introduced":"ac9f2af4349c7006a84a11f969eb51111d1383a5"},{"last_affected":"ac9f2af4349c7006a84a11f969eb51111d1383a5"}],"database_specific":{"cpe":"cpe:2.3:a:hyper:h2:0.2.4:*:*:*:*:rust:*:*","extracted_events":[{"introduced":"0.2.4"},{"last_affected":"0.2.4"}],"source":"CPE_STRING"}}],"versions":["0.2.4","v0.2.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26964.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/hyperium/hyper","events":[{"introduced":"4216b2de705f853d566ce185cae01ca99c63c9a1"},{"last_affected":"4216b2de705f853d566ce185cae01ca99c63c9a1"}],"database_specific":{"cpe":"cpe:2.3:a:hyper:hyper:0.13.7:*:*:*:*:rust:*:*","extracted_events":[{"introduced":"0.13.7"},{"last_affected":"0.13.7"}],"source":"CPE_STRING"}}],"versions":["0.13.7","v0.13.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26964.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26964.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZHBAE7LQARMPUEEV4TWET4D7G6WCWBUD/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZYRZ5Y2ALATKKPIITAFAJIS4TR4LUAHO/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26964"},{"type":"REPORT","url":"https://github.com/hyperium/hyper/issues/2877"}],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26964.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}