CVE-2026-55213 | h2o QPACK lib/http3/qpack.c alloca stack-based overflow

SecurityVulns

A vulnerability has been found in h2o and classified as problematic. This impacts the function alloca of the file lib/http3/qpack.c of the component QPACK Handler. The manipulation leads to stack-based buffer overflow.

This vulnerability is traded as CVE-2026-55213. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More