天下漏洞,尽知其名
CRITICAL

CVE-2026-78663 HTTP/2 服务器流控绕过漏洞

影响攻击者可绕过连接级流控限制,造成内存资源耗尽

AI 研判

该漏洞影响 HTTP/2 服务器实现,涉及连接级流量控制(flow control)的退款逻辑缺陷。当客户端重置流时,服务器会退还已发送但未读取数据的流控额度,而请求处理器读取缓冲数据时又再次退还同一份数据,导致连接级流控额度被重复退还。恶意客户端可利用此缺陷绕过 MaxReceiveBufferPerConnection 配置限制。

影响范围

HTTP/2 服务器

受影响的具体产品与版本范围暂无公开信息,需参考对应 HTTP/2 服务器实现的官方公告确认。

漏洞详情

漏洞类型为流量控制绕过(资源管理缺陷)。成因是连接级流控额度在流重置和缓冲数据读取两个路径上被重复退还,导致额度虚增。攻击者通过构造恶意客户端反复重置流并触发处理器读取,即可突破连接级接收缓冲上限。总缓冲数据仍受并发流限制和流级流控约束。

利用条件与风险

利用前提是攻击者能作为客户端与目标 HTTP/2 服务器建立连接并控制流重置行为。实战中可导致服务器内存资源被过度占用,可能引发拒绝服务。

修复建议

官方修复方案与临时缓解措施暂无公开信息,建议关注对应 HTTP/2 服务器实现的官方安全公告并及时升级。

原始情报

The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control.