GHSA-h3q4-6j7f-r24c
MODERATECVE-2016-6580A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream, and would therefore allocate unbounded amounts of memory. Attempting to actually us
- Affected
- >= 0, < 1.2.0
- Fixed in
- 1.2.0
- Weakness
- CWE-770
- Published
- 2022-05-17
- Source
- github