Skip to content
Critical Vulnerability in Fedora's perl-Protocol::HTTP2 Exposes Admin Control Risks

Critical Vulnerability in Fedora's perl-Protocol::HTTP2 Exposes Admin Control Risks

First seen 15 Sep 2026, 10:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 11:56 UTC
  • CVE-2026-16028 enables admin control via memory exhaustion.
  • Affected Fedora versions include 43, 44, and 45.
  • Immediate patching is recommended to mitigate risks.

A critical vulnerability (CVE-2026-16028) in Fedora's perl-Protocol::HTTP2 allows attackers to gain administrative control through chained flaws. This vulnerability, which causes memory exhaustion leading to denial of service, affects multiple Fedora versions, including 43, 44, and 45. The issue was disclosed on September 7, 2026, and is linked to unremoved closed streams in the HTTP/2 protocol implementation. Users are urged to upgrade to the latest version to mitigate risks. The vulnerability has been confirmed and is associated with an advisory issued by Petr Pisar. The update can be installed using the 'dnf' update program. Organizations using Fedora should prioritize applying the patch to prevent potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-07
CVE-2026-16028 published
A critical vulnerability in perl-Protocol::HTTP2 was disclosed, allowing for denial of service through memory exhaustion.
Linuxsecurity
2026-09-15
Advisory issued for Fedora 43, 44, and 45
Updates were released to fix CVE-2026-16028, urging users to upgrade to prevent exploitation.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-16028 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed