Filtered by vendor Quic-go Subscriptions
Filtered by product Webtransport-go Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-21438 1 Quic-go 1 Webtransport-go 2026-02-17 5.3 Medium
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Closed streams were not removed from an internal session map, preventing garbage collection of their resources. This vulnerability is fixed in v0.10.0.
CVE-2026-21435 1 Quic-go 1 Webtransport-go 2026-02-17 5.3 Medium
webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport session closure. A malicious peer can withhold QUIC flow control credit on the CONNECT stream, blocking transmission of the WT_CLOSE_SESSION capsule and causing the close operation to hang. This vulnerability is fixed in v0.10.0.