CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6601

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table

Protocol::HTTP2, a Perl module for HTTP/2 communication, contains a memory exhaustion vulnerability in versions before 1.14. The flaw allows attackers to exhaust memory by triggering closed streams that stream_state fails to remove from the connection stream table. Developers using the affected module should upgrade to version 1.14 or later.

Why it matters: Perl developers and operators running applications that depend on Protocol::HTTP2 before 1.14 face denial of service risk from memory exhaustion attacks; patch immediately to prevent service degradation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary