Alerts This Week
Warning Icon 1 548
Alerts This Week
Warning Icon 1 548

Fedora 44 perl-Protocol-HTTP2 Critical DoS Fix 2026-12765c0719

fedora
Calendar Grey June 17, 2026
Dist Fedora Esm H88
Fix for critical memory exhaustion issue in perl-Protocol-HTTP2 for Fedora 44, enhancing stability and performance.
This release fixes CVE-2026-10725 (exhausting memory when decompressing request headers)

Summary

Protocol::HTTP2 is Perl HTTP/2 protocol implementation (RFC 7540) with

stateful decoders/encoders of HTTP/2 frames. You may use this module to

implement your own HTTP/2 client/server/intermediate on top of your favorite

event loop over plain or TLS socket.

Update Information:

This release fixes CVE-2026-10725 (exhausting memory when decompressing request headers). It also improves examples.

Change Log

* Mon Jun 8 2026 Petr Pisar - 1.13-1 - 1.13 bump

References


[ 1 ] Bug #2485660 - CVE-2026-10725 Protocol::HTTP2: Protocol::HTTP2: Denial of Service via HTTP/2 Bomb https://bugzilla.redhat.com/show_bug.cgi?id=2485660

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-12765c0719' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: perl-Protocol-HTTP2
Product: Fedora 44
Version: 1.13
Release: 1.fc44
Summary: HTTP/2 protocol implementation (RFC 7540)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here