hpack: golang.org/x/net/http2/hpack: hpack: Denial of Service via malformed HTTP/2 header encoding
cve CVE-2026-59980 3 sources, 4 claims · Watch
Red Hat writes:
hpack: golang.org/x/net/http2/hpack: hpack: Denial of Service via malformed HTTP/2 header encoding the claim
hpack: golang.org/x/net/http2/hpack: hpack: Denial of Service via malformed HTTP/2 header encoding the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | python_hyper/hpackNVD says “python-hyper · hpack” |
| made_by | python_hyperNVD says “python-hyper” |
What each source says
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Cvss cvss | Red Hat | 5.3receipt
What the source handed over{
"CVE": "CVE-2026-59980",
"CWE": "CWE-770",
"advisories": [],
"affected_packages": [],
"bugzilla": "2539827",
"bugzilla_description": "hpack: golang.org/x/net/http2/hpack: hpack: Denial of Service via malformed HTTP/2 header encoding",
"cvss3_score": "5.3",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-23T22:07:35Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-59980.json",
"severity": "low"
} | — | ||||
| Cwe cwe not compared | GitHub advisories | CWE-400receipt
This source has not kept a receipt for this claim yet. The next update that reads it will. | — | ||||
| Cwe cwe not compared | Red Hat | CWE-770receipt
What the source handed over{
"CVE": "CVE-2026-59980",
"CWE": "CWE-770",
"advisories": [],
"affected_packages": [],
"bugzilla": "2539827",
"bugzilla_description": "hpack: golang.org/x/net/http2/hpack: hpack: Denial of Service via malformed HTTP/2 header encoding",
"cvss3_score": "5.3",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-23T22:07:35Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-59980.json",
"severity": "low"
} | — | ||||
| Ecosystem ecosystem | GitHub advisories | pipreceipt
This source has not kept a receipt for this claim yet. The next update that reads it will. | — | ||||
| Product product | NVD | hpackreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "hpack",
"vendor": "python-hyper",
"versions": [
{
"status": "affected",
"version": "< 4.2.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large enough unsanitized input. A fix is available in python-hyper/hpack v4.2.0 to restricted variable integer decoding to uint32 to prevent run-away computation. As a workaround, sanitize input to hpack decoder for long sequences of `0xFF` values to prevent malicious use."
}
],
"id": "CVE-2026-59980",
"lastModified": "2026-09-30T17:32:07.107",
"metrics": {
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-59980",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T13:24:31.887152Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-23T23:17:11.473",
"references": [
{
"source": "security-advisories@github.com",
"url": "https://cs.opensource.google/go/x/net/+/master:http2/hpack/hpack.go;l=468;drc=8e2b117aee74f6b86c207a808b0255de45c0a18a"
},
{
"source": "security-advisories@github.com",
"url": "https://docs.rs/http2/0.5.19/src/http2/hpack/decoder.rs.html#403"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-400"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity conflict | GitHub advisories | mediumreceipt
This source has not kept a receipt for this claim yet. The next update that reads it will. | — | ||||
| Severity severity conflict | Red Hat | low A flaw that is unlikely to be exploited, or whose impact is minimal. receipt
What the source handed over{
"CVE": "CVE-2026-59980",
"CWE": "CWE-770",
"advisories": [],
"affected_packages": [],
"bugzilla": "2539827",
"bugzilla_description": "hpack: golang.org/x/net/http2/hpack: hpack: Denial of Service via malformed HTTP/2 header encoding",
"cvss3_score": "5.3",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-23T22:07:35Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-59980.json",
"severity": "low"
} | — | ||||
| Status status | NVD | Deferredreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "hpack",
"vendor": "python-hyper",
"versions": [
{
"status": "affected",
"version": "< 4.2.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large enough unsanitized input. A fix is available in python-hyper/hpack v4.2.0 to restricted variable integer decoding to uint32 to prevent run-away computation. As a workaround, sanitize input to hpack decoder for long sequences of `0xFF` values to prevent malicious use."
}
],
"id": "CVE-2026-59980",
"lastModified": "2026-09-30T17:32:07.107",
"metrics": {
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-59980",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T13:24:31.887152Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-23T23:17:11.473",
"references": [
{
"source": "security-advisories@github.com",
"url": "https://cs.opensource.google/go/x/net/+/master:http2/hpack/hpack.go;l=468;drc=8e2b117aee74f6b86c207a808b0255de45c0a18a"
},
{
"source": "security-advisories@github.com",
"url": "https://docs.rs/http2/0.5.19/src/http2/hpack/decoder.rs.html#403"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-400"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | python-hyperreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "hpack",
"vendor": "python-hyper",
"versions": [
{
"status": "affected",
"version": "< 4.2.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large enough unsanitized input. A fix is available in python-hyper/hpack v4.2.0 to restricted variable integer decoding to uint32 to prevent run-away computation. As a workaround, sanitize input to hpack decoder for long sequences of `0xFF` values to prevent malicious use."
}
],
"id": "CVE-2026-59980",
"lastModified": "2026-09-30T17:32:07.107",
"metrics": {
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-59980",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T13:24:31.887152Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-23T23:17:11.473",
"references": [
{
"source": "security-advisories@github.com",
"url": "https://cs.opensource.google/go/x/net/+/master:http2/hpack/hpack.go;l=468;drc=8e2b117aee74f6b86c207a808b0255de45c0a18a"
},
{
"source": "security-advisories@github.com",
"url": "https://docs.rs/http2/0.5.19/src/http2/hpack/decoder.rs.html#403"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c"
},
{
"source": "security-advisories@github.com",
"url": "https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-400"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — |