« Volver al listado

CVE-2026-10725

Estado: AnalizadaAlta (7.5)—

Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb.

Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the "HTTP/2 bomb").

The headers_decode method materialises a full key+value copy per indexed reference with no running size check, and the stream_header_block_add method appends (since version 1.12) every CONTINUATION frame to the per-stream buffer unbounded.

MAX_HEADER_LIST_SIZE (default 65536) is advertised in SETTINGS but never consulted on decode. It is absent from the decoder and from the :limits export tag.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad remota en Protocol::HTTP2 (AV:N, PR:N, UI:N) explotable sin privilegios. Impacto: DoS por consumo de memoria (HTTP/2 bomb) mediante headers que se expanden sin límite, afectando disponibilidad del servidor.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-10725",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-10725",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-08T18:12:28.230486Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "affectedData": [
        {
          "repo": "https://github.com/vlet/p5-Protocol-HTTP2",
          "vendor": "CRUX",
          "product": "Protocol::HTTP2",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.13",
              "versionType": "custom"
            }
          ],
          "packageName": "Protocol-HTTP2",
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "Protocol::HTTP2::HeaderCompression::headers_decode"
            },
            {
              "name": "Protocol::HTTP2::Stream::stream_header_block_add"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-06T10:16:25.790",
  "references": [
    {
      "url": "https://github.com/vlet/p5-Protocol-HTTP2/commit/822bf22224adbd662e8d0b865eeacb2b294d16cd.patch",
      "tags": [
        "Patch"
      ],
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/CRUX/Protocol-HTTP2-1.12/source/lib/Protocol/HTTP2/HeaderCompression.pm#L133",
      "tags": [
        "Product"
      ],
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/CRUX/Protocol-HTTP2-1.12/source/lib/Protocol/HTTP2/Stream.pm#L414",
      "tags": [
        "Product"
      ],
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/CRUX/Protocol-HTTP2-1.13/changes",
      "tags": [
        "Release Notes"
      ],
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://security.metacpan.org/patches/P/Protocol-HTTP2/1.12/CVE-2026-10725-r2.patch",
      "tags": [
        "Patch"
      ],
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/06/06/7",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "description": [
        {
          "lang": "en",
          "value": "CWE-409"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb.\n\nProtocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the \"HTTP/2 bomb\").\n\nThe headers_decode method materialises a full key+value copy per indexed reference with no running size check, and the stream_header_block_add method appends (since version 1.12) every CONTINUATION frame to the per-stream buffer unbounded.\n\nMAX_HEADER_LIST_SIZE (default 65536) is advertised in SETTINGS but never consulted on decode.  It is absent from the decoder and from the :limits export tag."
    },
    {
      "lang": "es",
      "value": "Las versiones de Protocol::HTTP2 anteriores a la 1.13 para Perl son vulnerables a una bomba HTTP/2.\n\nLa ruta HPACK de entrada de Protocol::HTTP2 no tiene límite de tamaño para la lista de encabezados, por lo que una pequeña solicitud HTTP/2 puede expandirse en una gran cantidad de memoria del servidor (la 'bomba HTTP/2').\n\nEl método headers_decode materializa una copia completa de clave+valor por referencia indexada sin una verificación de tamaño en ejecución, y el método stream_header_block_add añade (desde la versión 1.12) cada trama CONTINUATION al búfer por flujo sin límites.\n\nMAX_HEADER_LIST_SIZE (valor predeterminado 65536) se anuncia en SETTINGS pero nunca se consulta durante la decodificación. Está ausente del decodificador y de la etiqueta de exportación :limits."
    }
  ],
  "lastModified": "2026-07-23T07:10:00.113",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:crux:protocol\\:\\:http2:*:*:*:*:*:perl:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61F9FFF8-0FE0-4D08-B0ED-13735781D313",
              "versionEndExcluding": "1.13"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}