Description
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
Published: 2026-04-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pc3f-x583-g7j2 SpdyStream: DOS on CRI
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:11070 cve-icon
https://access.redhat.com/errata/RHSA-2026:11217 cve-icon
https://access.redhat.com/errata/RHSA-2026:12118 cve-icon
https://access.redhat.com/errata/RHSA-2026:13791 cve-icon
https://access.redhat.com/errata/RHSA-2026:13829 cve-icon
https://access.redhat.com/errata/RHSA-2026:17121 cve-icon
https://access.redhat.com/errata/RHSA-2026:17123 cve-icon
https://access.redhat.com/errata/RHSA-2026:17449 cve-icon
https://access.redhat.com/errata/RHSA-2026:17468 cve-icon
https://access.redhat.com/errata/RHSA-2026:17469 cve-icon
https://access.redhat.com/errata/RHSA-2026:17475 cve-icon
https://access.redhat.com/errata/RHSA-2026:17598 cve-icon
https://access.redhat.com/errata/RHSA-2026:17599 cve-icon
https://access.redhat.com/errata/RHSA-2026:17704 cve-icon
https://access.redhat.com/errata/RHSA-2026:19099 cve-icon
https://access.redhat.com/errata/RHSA-2026:19108 cve-icon
https://access.redhat.com/errata/RHSA-2026:20034 cve-icon
https://access.redhat.com/errata/RHSA-2026:20041 cve-icon
https://access.redhat.com/errata/RHSA-2026:20042 cve-icon
https://access.redhat.com/errata/RHSA-2026:20089 cve-icon
https://access.redhat.com/errata/RHSA-2026:21658 cve-icon
https://access.redhat.com/errata/RHSA-2026:21692 cve-icon
https://access.redhat.com/errata/RHSA-2026:21697 cve-icon
https://access.redhat.com/errata/RHSA-2026:23235 cve-icon
https://access.redhat.com/errata/RHSA-2026:25009 cve-icon
https://access.redhat.com/errata/RHSA-2026:25046 cve-icon
https://access.redhat.com/errata/RHSA-2026:25187 cve-icon
https://access.redhat.com/errata/RHSA-2026:25194 cve-icon
https://access.redhat.com/errata/RHSA-2026:25201 cve-icon
https://access.redhat.com/errata/RHSA-2026:25207 cve-icon
https://access.redhat.com/errata/RHSA-2026:27004 cve-icon
https://access.redhat.com/errata/RHSA-2026:27010 cve-icon
https://access.redhat.com/errata/RHSA-2026:27063 cve-icon
https://access.redhat.com/errata/RHSA-2026:27903 cve-icon
https://access.redhat.com/errata/RHSA-2026:27914 cve-icon
https://access.redhat.com/errata/RHSA-2026:27941 cve-icon
https://access.redhat.com/errata/RHSA-2026:27983 cve-icon
https://access.redhat.com/errata/RHSA-2026:29795 cve-icon
https://access.redhat.com/errata/RHSA-2026:29801 cve-icon
https://access.redhat.com/errata/RHSA-2026:29835 cve-icon
https://access.redhat.com/errata/RHSA-2026:29857 cve-icon
https://access.redhat.com/errata/RHSA-2026:29858 cve-icon
https://access.redhat.com/errata/RHSA-2026:29865 cve-icon
https://access.redhat.com/errata/RHSA-2026:33071 cve-icon
https://access.redhat.com/errata/RHSA-2026:33078 cve-icon
https://access.redhat.com/errata/RHSA-2026:34050 cve-icon
https://access.redhat.com/errata/RHSA-2026:34099 cve-icon
https://access.redhat.com/errata/RHSA-2026:34100 cve-icon
https://access.redhat.com/errata/RHSA-2026:34755 cve-icon
https://access.redhat.com/errata/RHSA-2026:34766 cve-icon
https://access.redhat.com/errata/RHSA-2026:34769 cve-icon
https://access.redhat.com/errata/RHSA-2026:34791 cve-icon
https://access.redhat.com/errata/RHSA-2026:34794 cve-icon
https://access.redhat.com/errata/RHSA-2026:36162 cve-icon
https://access.redhat.com/errata/RHSA-2026:36621 cve-icon
https://access.redhat.com/errata/RHSA-2026:36796 cve-icon
https://access.redhat.com/errata/RHSA-2026:37187 cve-icon
https://access.redhat.com/errata/RHSA-2026:37193 cve-icon
https://access.redhat.com/errata/RHSA-2026:37387 cve-icon
https://access.redhat.com/errata/RHSA-2026:37580 cve-icon
https://access.redhat.com/errata/RHSA-2026:37581 cve-icon
https://access.redhat.com/errata/RHSA-2026:37629 cve-icon
https://access.redhat.com/errata/RHSA-2026:40022 cve-icon
https://access.redhat.com/errata/RHSA-2026:40023 cve-icon
https://access.redhat.com/errata/RHSA-2026:40030 cve-icon
https://access.redhat.com/errata/RHSA-2026:40828 cve-icon
https://access.redhat.com/errata/RHSA-2026:41019 cve-icon
https://access.redhat.com/errata/RHSA-2026:43227 cve-icon
https://access.redhat.com/errata/RHSA-2026:43253 cve-icon
https://access.redhat.com/errata/RHSA-2026:44237 cve-icon
https://access.redhat.com/errata/RHSA-2026:44267 cve-icon
https://access.redhat.com/errata/RHSA-2026:47728 cve-icon
https://access.redhat.com/errata/RHSA-2026:47729 cve-icon
https://access.redhat.com/errata/RHSA-2026:51007 cve-icon
https://access.redhat.com/errata/RHSA-2026:51013 cve-icon
https://access.redhat.com/errata/RHSA-2026:51022 cve-icon
https://access.redhat.com/errata/RHSA-2026:51422 cve-icon
https://access.redhat.com/errata/RHSA-2026:53655 cve-icon
https://access.redhat.com/security/cve/CVE-2026-35469 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2457729 cve-icon
https://github.com/moby/spdystream/releases/tag/v0.5.1 cve-icon cve-icon
https://github.com/moby/spdystream/security/advisories/GHSA-pc3f-x583-g7j2 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-35469 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35469.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-35469 cve-icon
History

Thu, 13 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 12 Aug 2026 12:30:00 +0000


Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
References

Fri, 17 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the SPDY streaming code used by Kubelet, CRI-O, and kube-apiserver. An attacker with specific cluster roles, such as those allowing access to pod port forwarding, execution, or attachment, or node proxying, could exploit this vulnerability. This could lead to a Denial of Service (DoS) by causing the affected components to become unresponsive. spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
Title Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code SpdyStream: DOS on CRI
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Thu, 16 Apr 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Kubernetes
Kubernetes kubelet
Vendors & Products Kubernetes
Kubernetes kubelet

Thu, 16 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the SPDY streaming code used by Kubelet, CRI-O, and kube-apiserver. An attacker with specific cluster roles, such as those allowing access to pod port forwarding, execution, or attachment, or node proxying, could exploit this vulnerability. This could lead to a Denial of Service (DoS) by causing the affected components to become unresponsive.
Title Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Subscriptions

Kubernetes Kubelet
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-14T12:04:40.888Z

Reserved: 2026-04-02T20:49:44.452Z

Link: CVE-2026-35469

cve-icon Vulnrichment

Updated: 2026-08-14T12:04:40.888Z

cve-icon NVD

Status : Deferred

Published: 2026-04-16T22:16:37.920

Modified: 2026-08-14T13:18:22.350

Link: CVE-2026-35469

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-13T23:59:59Z

Links: CVE-2026-35469 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T03:00:08Z

Weaknesses