moby Vulnerabilities and Affected Products
Vulnerabilities associated with spdystream.
Products
Clear product- moby19 vulnerabilities
- buildkit12 vulnerabilities
- hyperkit5 vulnerabilities
- Docker Engine1 vulnerability
- moby/v2/daemon1 vulnerability
- spdystream1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-35469HIGH | SpdyStream: DOS on CRIspdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a … CWE-770Apr 16, 2026 | CVSS8.7v4.0 | EPSS0.656% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |