highCVSS 7.5Vulnerability

GHSA-cjcg-cxmh-9wcr

### Summary Multiple denial-of-service vulnerabilities have been discovered in HTTP/2 server implementations. All have been rated with a severity impact of [Important](https://access.redhat.com/security/updates/classification). The vulnerabilities target HPACK, the header compression scheme in HTTP/2, where a small request can trigger large memory allocations on the server. ### Details Credit to the original researcher, I'm mostly just run their tool against the code base. [Security Bulletins](https://access.redhat.com/security/vulnerabilities/RHSB-2026-007): https://access.redhat.com/security/vulnerabilities/RHSB-2026-007 Exploit details: https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb This bug was fixed in upstream pingora v0.8.1, but our fork (v0.8.2) is missing this important [PR](https://github.com/praxis-proxy/pingora/commit/d193c8d49b8b7c1c1ede93183759caa4f6906bbd) to set the default h2 options. (edited) ### PoC * Generate certificates ``` openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -keyout server.key -out server.crt -days 3650 -nodes -subj "/CN=localhost" ``` * Create praxis config as follow ``` listeners: - name: web address: "0.0.0.0:8443" tls: certificates: - cert_path: /etc/praxis/server.crt key_path: /etc/praxis/server.key filter_chains: [main] filter_chains: - name: main filters: - filter: router routes: - path_prefix: "/" host: "example.api.com" cluster: backend - filter: load_balancer clusters: - name: backend endpoints: - "httpbingo.org:443" tls: verify: false ``` * Start the container ``` docker run --name praxis --user $(id -u):$(id -g) -it --rm -p 8443:8443 -v ./config.yaml:/etc/praxis/config.yaml -v ./server.crt:/etc/praxis/server.crt -v ./server.key:/etc/praxis/server.key ghcr.io/praxis-proxy/praxis:0.5.1 ``` * Check container

Properties

severity
high
summary
Praxis affected by HTTP/2 Bomb
cvss_score
7.5
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T23:09:37Z
source_url
https://github.com/advisories/GHSA-cjcg-cxmh-9wcr
ghsa_updated
2026-10-02T23:09:38Z
ghsa_id
GHSA-cjcg-cxmh-9wcr
last_source
GitHub Advisory Database
cve_id
GHSA-cjcg-cxmh-9wcr
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true

Related Entities (4)

VULNERABLE_TO (1)

←[Software]rust/praxis-proxy

AFFECTS (1)

→[Software]rust/praxis-proxy

HAS_WEAKNESS (1)

→[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph