CVE-2026-10725: Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb
Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb.
Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the "HTTP/2 bomb").
The headersdecode method materialises a full key+value copy per indexed reference with no running size check, and the streamheaderblockadd method appends (since version 1.12) every CONTINUATION frame to the per-stream buffer unbounded.
MAXHEADERLISTSIZE (default 65536) is advertised in SETTINGS but never consulted on decode. It is absent from the decoder and from the :limits export tag.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Protocol::HTTP2to a version that resolves this vulnerability.Fixed in 1.13 - Configuration
Ensure the decoder consults and enforces the advertised MAX_HEADER_LIST_SIZE (65536) when decoding header blocks. If possible, reduce the advertised limit and enforce a per-stream header-list size check to prevent unbounded header expansion.
Protocol::HTTP2 MAX_HEADER_LIST_SIZE = 65536 - Compensating control
Deploy network-level protections (WAF, reverse proxy, or firewall rules) to limit HTTP/2 header list sizes and to block or rate-limit excessive CONTINUATION frames per stream to mitigate memory-amplification attacks until the library is updated.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10725?
CVE-2026-10725 has a risk rating of 30.
How do I fix CVE-2026-10725?
To fix CVE-2026-10725, upgrade Protocol::HTTP2 to version 1.13 or later.
What types of systems are affected by CVE-2026-10725?
CVE-2026-10725 affects systems using Protocol::HTTP2 versions through 1.12 for Perl.
What is the nature of the vulnerability in CVE-2026-10725?
CVE-2026-10725 is a vulnerability that allows an HTTP/2 Bomb to exploit memory limits due to an absence of header-list size limits.
What is an HTTP/2 Bomb as described in CVE-2026-10725?
An HTTP/2 Bomb is a small HTTP/2 request that can expand into a large amount of server memory.