Skip to main content
EPSS 0.7%top 51%

CVE-2026-35469: CWE-770: Allocation of Resources Without Limits or Throttling in moby spdystream

0
High
VulnerabilityCVE-2026-35469cvecve-2026-35469cwe-770
Published: 04/16/2026 (04/16/2026, 21:19:23 UTC)
Source: CVE Database V5
Vendor/Project: moby
Product: spdystream

Description

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected software

moby

spdystream

Affected versions
<0.5.1
github.com/moby/spdystream
pkg:golang/github.com/moby/spdystream
Affected versions
<0.5.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 14:22:44 UTC

Technical Analysis

The vulnerability in spdystream (CVE-2026-35469) arises from the SPDY/3 frame parser failing to validate counts and lengths before memory allocation, specifically in SETTINGS frame entry counts, header counts, and individual header field sizes. These values are attacker-controlled and read as 32-bit integers without bounds checking, enabling a small compressed SPDY payload to decompress into large memory allocations. This can cause out-of-memory crashes in services using spdystream, including Kubernetes components Kubelet, CRI-O, and kube-apiserver. Exploitation requires elevated cluster roles permitting pod port forwarding, exec, attach, or node proxying. The issue is fixed in spdystream version 0.5.1. Red Hat advisories recommend restricting these Kubernetes cluster roles to trusted entities to mitigate risk.

Potential Impact

Successful exploitation leads to denial of service by exhausting process memory, causing critical Kubernetes components (Kubelet, CRI-O, kube-apiserver) to become unresponsive. This impacts availability of container orchestration and management services. No confidentiality or integrity impact is reported. The attack requires network access and specific elevated cluster roles, limiting the attack surface to privileged users or compromised accounts.

Mitigation Recommendations

A fix is available in spdystream version 0.5.1. Users should upgrade to this version or later. Additionally, restrict Kubernetes cluster roles that allow pod port forwarding (pods/portforward create), pod execution (pods/exec create), pod attachment (pods/attach create), and node proxying (nodes/proxy get/create) to trusted users and service accounts only. Modifying RBAC policies should be carefully tested to avoid disrupting legitimate operations. No other immediate actions are required once patched or mitigated by role restriction.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-04-02T20:49:44.452Z
Cvss Version
4.0
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-35469","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17704","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13829","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11070","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11217","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13791","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33078","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33071","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27914","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27983","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27903","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27941","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21697","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21692","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25009","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23235","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:20089","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25046","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17599","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17598","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17449","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:12118","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21658","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25201","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:20042","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27004","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:20041","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25194","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17469","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27063","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17468","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25187","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17475","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:20034","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25207","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27010","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19099","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19108","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17121","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17123","vendor":"Red Hat"}]

Threat ID: 69e1554682d89c981fce0d7f

Added to database: 04/16/2026, 21:31:50 UTC

Last enriched: 08/15/2026, 14:22:44 UTC

Last updated: 09/11/2026, 12:17:30 UTC

Views: 209

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses