Psl\H2\ServerConnection does not validate that the total bytes received in DATA frames match the content-length header declared in the HEADERS frame, in violation of RFC 9113 §8.1.1.
A malicious client can:
The vulnerability is only reachable for consumers using Psl\H2\ServerConnection directly to accept untrusted client traffic. The high-level Psl\HTTP\Server is in active development and was not yet released at the time of this advisory; consumers of documented high-level PSL APIs are not affected.
content-length header on incoming HEADERS (server-side only — clients do not enforce this per RFC 9110 §9.3.2).StreamException on mismatch or overflow.Regression tests landed in #781, 9 of the new tests fail against the pre-fix code, proving the validation boundary is enforced.
None at the protocol layer. Applications using Psl\H2\ServerConnection directly should upgrade.
{
"cwe_ids": [
"CWE-444"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-26T20:55:55Z",
"nvd_published_at": "2026-06-17T21:16:23Z",
"severity": "HIGH"
}