CVE-2026-35469: CWE-770: Allocation of Resources Without Limits or Throttling in moby spdystream
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
AI Analysis
Technical Summary
The vulnerability in spdystream (CVE-2026-35469) arises from the SPDY/3 frame parser failing to validate counts and lengths before memory allocation, specifically in SETTINGS frame entry counts, header counts, and individual header field sizes. These values are attacker-controlled and read as 32-bit integers without bounds checking, enabling a small compressed SPDY payload to decompress into large memory allocations. This can cause out-of-memory crashes in services using spdystream, including Kubernetes components Kubelet, CRI-O, and kube-apiserver. Exploitation requires elevated cluster roles permitting pod port forwarding, exec, attach, or node proxying. The issue is fixed in spdystream version 0.5.1. Red Hat advisories recommend restricting these Kubernetes cluster roles to trusted entities to mitigate risk.
Potential Impact
Successful exploitation leads to denial of service by exhausting process memory, causing critical Kubernetes components (Kubelet, CRI-O, kube-apiserver) to become unresponsive. This impacts availability of container orchestration and management services. No confidentiality or integrity impact is reported. The attack requires network access and specific elevated cluster roles, limiting the attack surface to privileged users or compromised accounts.
Mitigation Recommendations
A fix is available in spdystream version 0.5.1. Users should upgrade to this version or later. Additionally, restrict Kubernetes cluster roles that allow pod port forwarding (pods/portforward create), pod execution (pods/exec create), pod attachment (pods/attach create), and node proxying (nodes/proxy get/create) to trusted users and service accounts only. Modifying RBAC policies should be carefully tested to avoid disrupting legitimate operations. No other immediate actions are required once patched or mitigated by role restriction.
CVE-2026-35469: CWE-770: Allocation of Resources Without Limits or Throttling in moby spdystream
Description
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
CVSS v4.0
Score 8.7high
Affected software
moby
spdystream
pkg:golang/github.com/moby/spdystreamRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in spdystream (CVE-2026-35469) arises from the SPDY/3 frame parser failing to validate counts and lengths before memory allocation, specifically in SETTINGS frame entry counts, header counts, and individual header field sizes. These values are attacker-controlled and read as 32-bit integers without bounds checking, enabling a small compressed SPDY payload to decompress into large memory allocations. This can cause out-of-memory crashes in services using spdystream, including Kubernetes components Kubelet, CRI-O, and kube-apiserver. Exploitation requires elevated cluster roles permitting pod port forwarding, exec, attach, or node proxying. The issue is fixed in spdystream version 0.5.1. Red Hat advisories recommend restricting these Kubernetes cluster roles to trusted entities to mitigate risk.
Potential Impact
Successful exploitation leads to denial of service by exhausting process memory, causing critical Kubernetes components (Kubelet, CRI-O, kube-apiserver) to become unresponsive. This impacts availability of container orchestration and management services. No confidentiality or integrity impact is reported. The attack requires network access and specific elevated cluster roles, limiting the attack surface to privileged users or compromised accounts.
Mitigation Recommendations
A fix is available in spdystream version 0.5.1. Users should upgrade to this version or later. Additionally, restrict Kubernetes cluster roles that allow pod port forwarding (pods/portforward create), pod execution (pods/exec create), pod attachment (pods/attach create), and node proxying (nodes/proxy get/create) to trusted users and service accounts only. Modifying RBAC policies should be carefully tested to avoid disrupting legitimate operations. No other immediate actions are required once patched or mitigated by role restriction.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-02T20:49:44.452Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-35469","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17704","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13829","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11070","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11217","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13791","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33078","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33071","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27914","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27983","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27903","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27941","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21697","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21692","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25009","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23235","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:20089","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25046","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17599","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17598","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17449","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:12118","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21658","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25201","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:20042","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27004","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:20041","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25194","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17469","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27063","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17468","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25187","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17475","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:20034","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25207","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27010","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19099","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19108","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17121","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17123","vendor":"Red Hat"}]
Threat ID: 69e1554682d89c981fce0d7f
Added to database: 04/16/2026, 21:31:50 UTC
Last enriched: 08/15/2026, 14:22:44 UTC
Last updated: 09/11/2026, 12:17:30 UTC
Views: 209
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.