Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-D8C136BE1DF27278BE1920A69C9A6667
HistoryMay 24, 2022 - 12:00 a.m.

Uncontrolled Resource Consumption

2022-05-2400:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
20
http/2
denial of service
ping floods
software
uncontrolled resource consumption
internal queue

EPSS

0.149

Percentile

95.9%

Some HTTP/2 implementations is vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.