Allocation of Resources Without Limits or Throttling Affecting hpack package, versions [,4.2.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-HPACK-20074632
  • published24 Sept 2026
  • disclosed23 Sept 2026
  • creditHiroki Nishino

Introduced: 23 Sep 2026

NewCVE-2026-59980  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade hpack to version 4.2.0 or higher.

Overview

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the decode_integer function in src/hpack/hpack.py, where an attacker can send an HPACK-encoded integer with an unbounded number of continuation octets, causing run-away computation that crashes the decoder. The HPACK RFC 7541 Section 5.1 explicitly permits values of indefinite size and notes that encoders can send large numbers of zero values to waste octets or overflow integer values, and the library did not enforce any limit on the number of octets consumed during variable-length integer decoding.

CVSS Base Scores

version 4.0
version 3.1