Description
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, retaining the complete declared capsule body in memory. A malicious peer can send a large unknown capsule and cause a client or server to allocate memory for the full payload; QUIC flow control does not bound the total retained allocation because reading advances the flow-control window while the received bytes remain in memory. The resulting memory and resource exhaustion can disrupt or crash the affected process. This issue is fixed in version 0.11.1.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service through Memory Exhaustion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in webtransport-go versions before 0.11.1. In those releases, Session.parseNextCapsule() skips unknown WebTransport capsules by reading the entire declared capsule body into memory with io.ReadAll before discarding it. A malicious peer can therefore send an arbitrarily large unknown capsule, causing the client or server to allocate memory for the full payload. Because QUIC flow control advances independently of the cached data, no bound limits the retained allocation, leading to unchecked memory growth that can disrupt or crash the v0.11.1.

Affected Systems

The issue affects the webtransport-go implementation from quic-go, specifically any version before 0.11.1. Both client and server sides that use the unpatched library are vulnerable. Users should confirm the version of the library in use and apply a fix if it falls within the affected range.

Risk and Exploitability

The CVSS score of 5.3 classifies the vulnerability as medium severity. The EPSS score of <1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited known exploitation. An attacker can exploit this remotely by sending an HTTP/3 request containing a large unknown capsule; no local privileges, authentication, or additional dependencies are required. Since the capsule is accepted and fully buffered before being discarded, a single unauthenticated connection can trigger memory exhaustion, potentially disrupting the service.

Generated by OpenCVE AI on September 20, 2026 at 23:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade webtransport-go to version 0.11.1 or later to apply the fixed logic that limits retained buffer size.
  • If upgrading is delayed, configure the server to reject or truncate unknown capsules before reading them entirely, or enforce a hard limit on the maximum size of any capsule payload.
  • Deploy network segmentation or rate limiting for HTTP/3 traffic to reduce the frequency of potentially malicious capsule deliveries and monitor memory usage on hosts running webtransport-go.

Generated by OpenCVE AI on September 20, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g35j-m5xg-vh3q webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
History

Tue, 15 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Quic-go
Quic-go webtransport-go
Vendors & Products Quic-go
Quic-go webtransport-go

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, retaining the complete declared capsule body in memory. A malicious peer can send a large unknown capsule and cause a client or server to allocate memory for the full payload; QUIC flow control does not bound the total retained allocation because reading advances the flow-control window while the received bytes remain in memory. The resulting memory and resource exhaustion can disrupt or crash the affected process. This issue is fixed in version 0.11.1.
Title webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Quic-go Webtransport-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:06:48.086Z

Reserved: 2026-06-24T14:53:40.111Z

Link: CVE-2026-57497

cve-icon Vulnrichment

Updated: 2026-09-14T19:22:15.425Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T17:17:49.097

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-57497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling