As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table
Protocol::HTTP2, a Perl module for HTTP/2 communication, contains a memory exhaustion vulnerability in versions before 1.14. The flaw allows attackers to exhaust memory by triggering closed streams that stream_state fails to remove from the connection stream table. Developers using the affected module should upgrade to version 1.14 or later.
Why it matters: Perl developers and operators running applications that depend on Protocol::HTTP2 before 1.14 face denial of service risk from memory exhaustion attacks; patch immediately to prevent service degradation.
- Source published
- First seen by Cybersecurity Tracker