Security Advisory

CVE-2026-21435

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-02-12 18:22:58
Last updated 2026-02-17 15:36:08
Assigner GitHub_M
CVSS score 5.3
State PUBLISHED

Description

webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport session closure. A malicious peer can withhold QUIC flow control credit on the CONNECT stream, blocking transmission of the WT_CLOSE_SESSION capsule and causing the close operation to hang. This vulnerability is fixed in v0.10.0.