Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/hyperium/hyper/compare/v0.14.18...v0.14.19 | Patch | 
| https://github.com/hyperium/hyper/issues/2826 | Exploit Issue Tracking Patch Vendor Advisory | 
| https://github.com/hyperium/hyper/pull/2828 | Issue Tracking Patch | 
| https://github.com/hyperium/hyper/compare/v0.14.18...v0.14.19 | Patch | 
| https://github.com/hyperium/hyper/issues/2826 | Exploit Issue Tracking Patch Vendor Advisory | 
| https://github.com/hyperium/hyper/pull/2828 | Issue Tracking Patch | 
Configurations
                    History
                    21 Nov 2024, 07:04
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/hyperium/hyper/compare/v0.14.18...v0.14.19 - Patch | |
| References | () https://github.com/hyperium/hyper/issues/2826 - Exploit, Issue Tracking, Patch, Vendor Advisory | |
| References | () https://github.com/hyperium/hyper/pull/2828 - Issue Tracking, Patch | 
Information
                Published : 2023-02-21 14:15
Updated : 2025-03-17 19:15
NVD link : CVE-2022-31394
Mitre link : CVE-2022-31394
CVE.ORG link : CVE-2022-31394
JSON object : View
Products Affected
                hyper
- hyper
 
CWE
                
                    
                        
                        CWE-770
                        
            Allocation of Resources Without Limits or Throttling
