CVE-2026-44453
Last modified
CVE-2026-44453 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the file path on stack, by calling alloca. The maximum size of the memory allocated using alloca can be as huge as ~600KB, which exceeds the default pthread stack size used by musl libc (128KB). If the amount of memory allocated by alloca exceeds the stack size, the h2o server crashes with a segmentation fault, while it tries to touch the guard page. This issue has been fixed by commit 6b5370d.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| H2o | H2o | < 2026-05-29 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-44453?
How severe is CVE-2026-44453?
How do I fix CVE-2026-44453?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44448ERPNext is a free and open source Enterprise Resource Planni…6.5
- CVE-2026-44449Lumiverse is a full-featured AI chat application. Prior to 0…9.1
- CVE-2026-4445Use after free in WebRTC in Google Chrome prior to 146.0.768…8.8
- CVE-2026-44450Lumiverse is a full-featured AI chat application. Prior to 0…9.9
- CVE-2026-44451Lumiverse is a full-featured AI chat application. Prior to 0…9.3
- CVE-2026-44452h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and …5.9
- CVE-2026-44454Coder allows organizations to provision remote development e…8.8
- CVE-2026-44455Hono is a Web application framework that provides support fo…6.1
- CVE-2026-44456Hono is a Web application framework that provides support fo…6.5
- CVE-2026-44457Hono is a Web application framework that provides support fo…5.3
- CVE-2026-44458Hono is a Web application framework that provides support fo…4.3
- CVE-2026-44459Hono is a Web application framework that provides support fo…3.8
Are you affected by CVE-2026-44453?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
