CVE-2022-31394: High severity hyper h2 vulnerability
Published Feb 21, 2023
·Updated
Hyperium Hyper before 0.14.19 does not allow for customization of the maxheaderlistsize method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.
Affected Software
1 affected component
hyper Hyper Rust<0.14.19
Remediation
Patch Available
Patch Available
Event History
Feb 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-31394?
CVE-2022-31394 is classified as a high severity vulnerability due to the potential for HTTP2 attacks.
2
How do I fix CVE-2022-31394?
To fix CVE-2022-31394, upgrade Hyper to version 0.14.19 or later.
3
What types of attacks can CVE-2022-31394 enable?
CVE-2022-31394 can enable attackers to exploit HTTP2 features, leading to denial of service attacks.
4
Is CVE-2022-31394 present in versions of Hyper prior to 0.14.19?
Yes, CVE-2022-31394 affects all versions of Hyper before 0.14.19.
5
What component of Hyper is affected by CVE-2022-31394?
The max_header_list_size method in the H2 component of Hyper is affected by CVE-2022-31394.