RUSTSEC-2026-0258: h2 unbounded empty DATA frames
Author: github-actions[bot]Created Aug 19, 2026Updated Aug 19, 2026
h2 unbounded empty DATA frames
| Details | |
|---|---|
| Package | h2 |
| Version | 0.3.27 |
| URL | https://github.com/hyperium/hyper/security/advisories/GHSA-q83h-524g-xf6h |
| Date | 2026-08-17 |
| Patched versions | >=0.4.16 |
The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.
Low severity.
Patched in v0.4.16.
See advisory page for additional details.
Source: FuelLabs/sway