CVE-2023-26964: Hyper h2

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).

Affected products

  • Hyper h2: version 0.2.4 only
  • Hyper Hyper: version 0.13.7 only

Published 2023-04-11. Last modified 2026-06-17.