Description
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
Remediation
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0093)
WordPress Plugin Widget for Facebook Page Feeds Cross-Site Scripting (5.0)
WordPress Plugin Instagram Plugin-InstaLinker Cross-Site Scripting (1.1.1)
Craft CMS Missing Authentication for Critical Function Vulnerability (CVE-2026-33159)