CVE-2026-35469Patch

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-06-21)
  • 9 total mentions across 6 days

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-04-17: 2Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Mentions · 2026-06-10: 1Mentions · 2026-06-19: 1Mentions · 2026-06-21: 3PoC Mentioned / Linked · 2026-06-21: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-06-21: 2Technical Details · 2026-04-17: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-21: 304-1704-1904-2006-1006-1906-21
Signal classification2 categories
Patch
555.6%
Disclosure
444.4%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-172
Disclosure1Patch1
2026-04-191
Patch1
2026-04-201
Patch1
2026-06-101
Disclosure1
2026-06-191
Disclosure1
2026-06-213
Disclosure1Patch2
Full discourse9 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - Go spdystream SPDY memory amplification DoS (CVE-2026-35469) Malformed SPDY control frames can trigger unbounded memory allocations, allowing a remote peer to cause OOM with a single crafted frame. 👉 Affected: <= v0.5.0 | Upgrade to v0.5.1 https://t.co/QPCumAfC2S

    Post summary

    The Go SPDYSTREAM library (CVE-2026-35469) allows a remote peer to trigger a DoS via malformed SPDY frames; users using v0.5.0 or earlier should upgrade to v0.5.1.

    0004098
    238 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔐 CVE-2026-35469: vulnerabilidade DoS no #Kubernetes 1.35 via SPDY streaming. Atualize para 1.35.6 AGORA. Saiba mais: -> https://tinyurl.com/ysrzhtbr #Fedora https://t.co/Di7KSBSTam

    Post summary

    The tweet highlights a DoS vulnerability in Kubernetes 1.35 (CVE-2026-35469) and urges users to update to version 1.35.6.

    1000053
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🛡️ ATENÇÃO ADMINISTRADORES KUBERNETES A CVE-2026-35469 expõe clusters Fedora a ataques de negação de serviço via SPDY. Um frame manipulado = memória esgotada = serviço fora do ar. Saiba mais: -> http://tinyurl.com/5xwvthw7 https://t.co/czfMD01d0b

    Post summary

    The post announces CVE‑2026‑35469 as enabling denial‑of‑service attacks on Fedora Kubernetes clusters via SPDY, detailing the memory‑exhaustion attack vector but offering no PoC or patch information.

    1000055
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔐 A CVE-2026-35469 expõe clusters #Kubernetes a DoS via SPDY. Aprenda a verificar, corrigir e mitigar no Fedora com um script pronto. Saiba mais: -> http://tinyurl.com/5fmjhyeb #Fedora https://t.co/5kYf5DcbpM

    Post summary

    The post highlights CVE‑2026‑35469, a DoS flaw in Kubernetes via SPDY, and offers a ready script for verification and mitigation on Fedora.

    1000054
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🛡️ #SUSE #Kubernetes: duas vulnerabilidades críticas (CVE-2026-33814 e CVE-2026-35469) permitem DoS remoto. Saiba mais: -> http://tinyurl.com/5ee7ab7u https://t.co/hmb5X7OqTa

    Post summary

    The tweet announces two critical Kubernetes CVEs enabling remote DoS, but provides no PoC, exploit, or patch details.

    1000048
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    CVE-2026-35469: um frame SPDY malicioso pode derrubar seu cluster inteiro. Aprenda a identificar, corrigir e mitigar essa falha no #openSUSE hoje mesmo . Saiba mais → https://tinyurl.com/bdcnvvmh https://t.co/6Pox4eNQef

    Post summary

    The tweet announces CVE-2026-35469, a malicious SPDY frame that can crash an OpenSUSE cluster, and advises users to identify, patch, and mitigate the issue.

    0000035
    1.5K followersView on X
  • Mario Fahlandt 🦊@mfahlandt
    Patch

    🛡️ Dapr, Containerd, Prometheus security updates. * Dapr v1.17.5+ fixed critical service invocation path traversal. * Containerd v2.2.3+ patched CVE-2026-35469 (spdystream). * Prometheus v3.11.2+ fixed Stored XSS in web UI. Full breakdown: https://www.lwcn.dev/newsletter/2026-week-17/

    Post summary

    The announcement lists security patches for Dapr, Containerd, and Prometheus, detailing each vulnerability’s nature and the versions that address them.

    0000069
    501 followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-35469 is the classic “oops, our infrastructure code can get stuck” DoS. Availability bugs hit hardest because everyone blames you—until patch day. https://windowsforum.com/threads/cve-2026-35469-spdystream-dos-in-cri-patch-guidance-for-defender-teams.413963/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #DenialOfService #MicrosoftSecurityUpdateGuide #Cve202635469 #ContainerRuntimeInterface

    Post summary

    The post highlights a DoS vulnerability (CVE-2026-35469) and links to a forum thread that includes patch guidance for Defender Teams, but does not provide technical exploitation details or evidence of active attacks.

    0000041
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35469 spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled … https://www.cve.org/CVERecord?id=CVE-2026-35469

    Post summary

    This excerpt announces CVE‑2026‑35469, noting that spdystream’s SPDY/3 frame parser fails to validate attacker‑controlled frames, but contains no PoC, exploit, or patch information.

    0000076
    57.2K followersView on X

Explore more