GHSA-cjcg-cxmh-9wcr
### Summary Multiple denial-of-service vulnerabilities have been discovered in HTTP/2 server implementations. All have been rated with a severity impact of [Important](https://access.redhat.com/security/updates/classification). The vulnerabilities target HPACK, the header compression scheme in HTTP/2, where a small request can trigger large memory allocations on the server. ### Details Credit to the original researcher, I'm mostly just run their tool against the code base. [Security Bulletins](https://access.redhat.com/security/vulnerabilities/RHSB-2026-007): https://access.redhat.com/security/vulnerabilities/RHSB-2026-007 Exploit details: https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb This bug was fixed in upstream pingora v0.8.1, but our fork (v0.8.2) is missing this important [PR](https://github.com/praxis-proxy/pingora/commit/d193c8d49b8b7c1c1ede93183759caa4f6906bbd) to set the default h2 options. (edited) ### PoC * Generate certificates ``` openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -keyout server.key -out server.crt -days 3650 -nodes -subj "/CN=localhost" ``` * Create praxis config as follow ``` listeners: - name: web address: "0.0.0.0:8443" tls: certificates: - cert_path: /etc/praxis/server.crt key_path: /etc/praxis/server.key filter_chains: [main] filter_chains: - name: main filters: - filter: router routes: - path_prefix: "/" host: "example.api.com" cluster: backend - filter: load_balancer clusters: - name: backend endpoints: - "httpbingo.org:443" tls: verify: false ``` * Start the container ``` docker run --name praxis --user $(id -u):$(id -g) -it --rm -p 8443:8443 -v ./config.yaml:/etc/praxis/config.yaml -v ./server.crt:/etc/praxis/server.crt -v ./server.key:/etc/praxis/server.key ghcr.io/praxis-proxy/praxis:0.5.1 ``` * Check container
Properties
- severity
- high
- summary
- Praxis affected by HTTP/2 Bomb
- cvss_score
- 7.5
- retrieved_at
- 2026-10-03T18:15:00+00:00
- ghsa_published
- 2026-10-02T23:09:37Z
- source_url
- https://github.com/advisories/GHSA-cjcg-cxmh-9wcr
- ghsa_updated
- 2026-10-02T23:09:38Z
- ghsa_id
- GHSA-cjcg-cxmh-9wcr
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-cjcg-cxmh-9wcr
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- signal_observed_at
- 2026-10-03T01:59:23+00:00
- is_ghsa_only
- true
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph