HIGHVulnerability

CVE-2026-44453

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the file path on stack, by calling alloca. The maximum size of the memory allocated using alloca can be as huge as ~600KB, which exceeds the default pthread stack size used by musl libc (128KB). If the amount of memory allocated by alloca exceeds the stack size, the h2o server crashes with a segmentation fault, while it tries to touch the guard page. This issue has been fixed by commit 6b5370d.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-44453
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-07-16T23:16:17.423
last_modified
2026-08-06T13:25:39.943

Related Entities (4)

HAS_WEAKNESS (2)

[Weakness]Memory Allocation with Excessive Size Value
[Weakness]Allocation of Resources Without Limits or Throttling

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-44453 — Ninja Signal Threat Intelligence | Ninja Signal