spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:11070 cve-icon
https://access.redhat.com/errata/RHSA-2026:11217 cve-icon
https://access.redhat.com/errata/RHSA-2026:12118 cve-icon
https://access.redhat.com/errata/RHSA-2026:13791 cve-icon
https://access.redhat.com/errata/RHSA-2026:13829 cve-icon
https://access.redhat.com/errata/RHSA-2026:17121 cve-icon
https://access.redhat.com/errata/RHSA-2026:17123 cve-icon
https://access.redhat.com/errata/RHSA-2026:17449 cve-icon
https://access.redhat.com/errata/RHSA-2026:17468 cve-icon
https://access.redhat.com/errata/RHSA-2026:17469 cve-icon
https://access.redhat.com/errata/RHSA-2026:17475 cve-icon
https://access.redhat.com/errata/RHSA-2026:17598 cve-icon
https://access.redhat.com/errata/RHSA-2026:17599 cve-icon
https://access.redhat.com/errata/RHSA-2026:17704 cve-icon
https://access.redhat.com/errata/RHSA-2026:19099 cve-icon
https://access.redhat.com/errata/RHSA-2026:19108 cve-icon
https://access.redhat.com/errata/RHSA-2026:20034 cve-icon
https://access.redhat.com/errata/RHSA-2026:20041 cve-icon
https://access.redhat.com/errata/RHSA-2026:20042 cve-icon
https://access.redhat.com/errata/RHSA-2026:20089 cve-icon
https://access.redhat.com/errata/RHSA-2026:21658 cve-icon
https://access.redhat.com/errata/RHSA-2026:21692 cve-icon
https://access.redhat.com/errata/RHSA-2026:21697 cve-icon
https://access.redhat.com/errata/RHSA-2026:23235 cve-icon
https://access.redhat.com/errata/RHSA-2026:25009 cve-icon
https://access.redhat.com/errata/RHSA-2026:25046 cve-icon
https://access.redhat.com/errata/RHSA-2026:25187 cve-icon
https://access.redhat.com/errata/RHSA-2026:25194 cve-icon
https://access.redhat.com/errata/RHSA-2026:25201 cve-icon
https://access.redhat.com/errata/RHSA-2026:25207 cve-icon
https://access.redhat.com/errata/RHSA-2026:27004 cve-icon
https://access.redhat.com/errata/RHSA-2026:27010 cve-icon
https://access.redhat.com/errata/RHSA-2026:27063 cve-icon
https://access.redhat.com/errata/RHSA-2026:27903 cve-icon
https://access.redhat.com/errata/RHSA-2026:27914 cve-icon
https://access.redhat.com/errata/RHSA-2026:27941 cve-icon
https://access.redhat.com/errata/RHSA-2026:27983 cve-icon
https://access.redhat.com/errata/RHSA-2026:29795 cve-icon
https://access.redhat.com/errata/RHSA-2026:29801 cve-icon
https://access.redhat.com/errata/RHSA-2026:29835 cve-icon
https://access.redhat.com/errata/RHSA-2026:29857 cve-icon
https://access.redhat.com/errata/RHSA-2026:29858 cve-icon
https://access.redhat.com/errata/RHSA-2026:29865 cve-icon
https://access.redhat.com/errata/RHSA-2026:33071 cve-icon
https://access.redhat.com/errata/RHSA-2026:33078 cve-icon
https://access.redhat.com/errata/RHSA-2026:34050 cve-icon
https://access.redhat.com/errata/RHSA-2026:34099 cve-icon
https://access.redhat.com/errata/RHSA-2026:34100 cve-icon
https://access.redhat.com/errata/RHSA-2026:34755 cve-icon
https://access.redhat.com/errata/RHSA-2026:34766 cve-icon
https://access.redhat.com/errata/RHSA-2026:34769 cve-icon
https://access.redhat.com/errata/RHSA-2026:34791 cve-icon
https://access.redhat.com/errata/RHSA-2026:34794 cve-icon
https://access.redhat.com/errata/RHSA-2026:36162 cve-icon
https://access.redhat.com/errata/RHSA-2026:36621 cve-icon
https://access.redhat.com/errata/RHSA-2026:36796 cve-icon
https://access.redhat.com/errata/RHSA-2026:37187 cve-icon
https://access.redhat.com/errata/RHSA-2026:37193 cve-icon
https://access.redhat.com/errata/RHSA-2026:37387 cve-icon
https://access.redhat.com/errata/RHSA-2026:37580 cve-icon
https://access.redhat.com/errata/RHSA-2026:37581 cve-icon
https://access.redhat.com/errata/RHSA-2026:37629 cve-icon
https://access.redhat.com/errata/RHSA-2026:40022 cve-icon
https://access.redhat.com/errata/RHSA-2026:40023 cve-icon
https://access.redhat.com/errata/RHSA-2026:40030 cve-icon
https://access.redhat.com/errata/RHSA-2026:40828 cve-icon
https://access.redhat.com/errata/RHSA-2026:41019 cve-icon
https://access.redhat.com/errata/RHSA-2026:43227 cve-icon
https://access.redhat.com/errata/RHSA-2026:43253 cve-icon
https://access.redhat.com/errata/RHSA-2026:44237 cve-icon
https://access.redhat.com/errata/RHSA-2026:44267 cve-icon
https://access.redhat.com/errata/RHSA-2026:47728 cve-icon
https://access.redhat.com/errata/RHSA-2026:47729 cve-icon
https://access.redhat.com/errata/RHSA-2026:51022 cve-icon
https://access.redhat.com/security/cve/CVE-2026-35469 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2457729 cve-icon
https://github.com/moby/spdystream/releases/tag/v0.5.1 cve-icon cve-icon
https://github.com/moby/spdystream/security/advisories/GHSA-pc3f-x583-g7j2 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-35469 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35469.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-35469 cve-icon
History

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
References

Fri, 17 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the SPDY streaming code used by Kubelet, CRI-O, and kube-apiserver. An attacker with specific cluster roles, such as those allowing access to pod port forwarding, execution, or attachment, or node proxying, could exploit this vulnerability. This could lead to a Denial of Service (DoS) by causing the affected components to become unresponsive. spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
Title Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code SpdyStream: DOS on CRI
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Thu, 16 Apr 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Kubernetes
Kubernetes kubelet
Vendors & Products Kubernetes
Kubernetes kubelet

Thu, 16 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the SPDY streaming code used by Kubelet, CRI-O, and kube-apiserver. An attacker with specific cluster roles, such as those allowing access to pod port forwarding, execution, or attachment, or node proxying, could exploit this vulnerability. This could lead to a Denial of Service (DoS) by causing the affected components to become unresponsive.
Title Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-11T12:04:43.667Z

Reserved: 2026-04-02T20:49:44.452Z

Link: CVE-2026-35469

cve-icon Vulnrichment

Updated: 2026-08-11T12:04:43.667Z

cve-icon NVD

Status : Deferred

Published: 2026-04-16T22:16:37.920

Modified: 2026-08-11T13:18:34.983

Link: CVE-2026-35469

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-13T23:59:59Z

Links: CVE-2026-35469 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T03:00:08Z