A newly disclosed denial-of-service flaw in multiple HTTP/2 server implementations allows remote, unauthenticated attackers to exhaust memory and crash services by abusing normal flow-control behavior. By stalling outbound data transmission—such as by manipulating SETTINGS_INITIAL_WINDOW_SIZE or withholding WINDOW_UPDATE frames—an attacker can cause vulnerable servers to keep generating and buffering full responses, leading to out-of-memory conditions, swap thrashing, worker-thread exhaustion, service freezes, or kernel OOM kills. CERT/CC is tracking the issue after it was reported by the Okta Red Team, and the coordinated disclosures include CVE-2026-44909, CVE-2026-59173, and CVE-2026-59762.
Affected vendors named in advisories include Apache Traffic Server, Citrix, F5 Networks, Meta, Red Hat, SUSE, and Yahoo. Apache Traffic Server users were advised to upgrade to versions 9.1.14 or 10.1.3, while F5 published guidance for BIG-IP and other vendors issued product-specific fixes or mitigations. Recommended defenses include stricter memory limits, limiting concurrent HTTP/2 streams, terminating stalled connections, and improving timeout and backpressure handling. No public exploitation has been confirmed, but the low complexity of the attack has prompted calls for rapid patching and configuration hardening.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The HTTP/2 denial-of-service issue was reported by the Okta Red Team. The flaw involves abusing normal flow-control behavior so servers buffer unsent response data until memory is exhausted.
Affected vendors including F5 began releasing fixes, advisories, and mitigations for the HTTP/2 memory-exhaustion flaw. Recommended defenses included stricter memory limits, limiting concurrent HTTP/2 streams, terminating stalled connections, and improving timeout and backpressure handling.
Apache Traffic Server published fixes or advisories for its affected HTTP/2 implementation. Users were advised to upgrade to versions 9.1.14 or 10.1.3.
CERT/CC began tracking the coordinated disclosure covering multiple CVEs affecting HTTP/2 implementations, including CVE-2026-44909, CVE-2026-59173, and CVE-2026-59762. The issue affects multiple vendors and can lead to freezes, crashes, or out-of-memory conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.