CVE-2026-35469
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/moby/spdystream/releases/tag/v0.5.1, https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35469.json, https://access.redhat.com/errata/RHSA-2026:11070, https://access.redhat.com/errata/RHSA-2026:11217, https://access.redhat.com/errata/RHSA-2026:12118, https://access.redhat.com/errata/RHSA-2026:13791, https://access.redhat.com/errata/RHSA-2026:13829, https://access.redhat.com/errata/RHSA-2026:17121, https://access.redhat.com/errata/RHSA-2026:17123, https://access.redhat.com/errata/RHSA-2026:17449, https://access.redhat.com/errata/RHSA-2026:17468, https://access.redhat.com/errata/RHSA-2026:17469, https://access.redhat.com/errata/RHSA-2026:17475, https://access.redhat.com/errata/RHSA-2026:17598, https://access.redhat.com/errata/RHSA-2026:17599, https://access.redhat.com/errata/RHSA-2026:17704, https://access.redhat.com/errata/RHSA-2026:19099, https://access.redhat.com/errata/RHSA-2026:19108, https://access.redhat.com/errata/RHSA-2026:20034, https://access.redhat.com/errata/RHSA-2026:20041, https://access.redhat.com/errata/RHSA-2026:20042, https://access.redhat.com/errata/RHSA-2026:20089, https://access.redhat.com/errata/RHSA-2026:21658, https://access.redhat.com/errata/RHSA-2026:21692, https://access.redhat.com/errata/RHSA-2026:21697, https://access.redhat.com/errata/RHSA-2026:23235, https://access.redhat.com/errata/RHSA-2026:25009, https://access.redhat.com/errata/RHSA-2026:25046, https://access.redhat.com/errata/RHSA-2026:25187, https://access.redhat.com/errata/RHSA-2026:25194, https://access.redhat.com/errata/RHSA-2026:25201, https://access.redhat.com/errata/RHSA-2026:25207, https://access.redhat.com/errata/RHSA-2026:27004, https://access.redhat.com/errata/RHSA-2026:27010, https://access.redhat.com/errata/RHSA-2026:27063, https://access.redhat.com/errata/RHSA-2026:27903, https://access.redhat.com/errata/RHSA-2026:27914, https://access.redhat.com/errata/RHSA-2026:27941, https://access.redhat.com/errata/RHSA-2026:27983, https://access.redhat.com/errata/RHSA-2026:29795, https://access.redhat.com/errata/RHSA-2026:29801, https://access.redhat.com/errata/RHSA-2026:29835, https://access.redhat.com/errata/RHSA-2026:29857, https://access.redhat.com/errata/RHSA-2026:29858, https://access.redhat.com/errata/RHSA-2026:29865, https://access.redhat.com/errata/RHSA-2026:33071, https://access.redhat.com/errata/RHSA-2026:33078, https://access.redhat.com/errata/RHSA-2026:34050, https://access.redhat.com/errata/RHSA-2026:34099, https://access.redhat.com/errata/RHSA-2026:34766, https://access.redhat.com/errata/RHSA-2026:34769, https://access.redhat.com/errata/RHSA-2026:34791, https://access.redhat.com/errata/RHSA-2026:34794, https://access.redhat.com/errata/RHSA-2026:36162, https://access.redhat.com/errata/RHSA-2026:36796, https://access.redhat.com/security/cve/CVE-2026-35469, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35469.json, https://github.com/moby/spdystream/security/advisories/GHSA-pc3f-x583-g7j2, https://nvd.nist.gov/vuln/detail/CVE-2026-35469, https://bugzilla.redhat.com/show_bug.cgi?id=2457729