cve-2026-40898
csaf_suse
Description
SUSE CVE-2026-40898
Timeline
- Published
- 2026-07-11 03:26 UTC
- Last Modified
- 2026-07-11
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "moderate"
},
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "SUSE CVE-2026-40898",
"title": "Title"
},
{
"category": "description",
"text": "quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique field names and/or large values. The implementation builds an `http.Header` for the corresponding `http.Request` or `http.Response`, while only enforcing limits on the size of the QPACK-compressed HEADERS frame, not on the decoded field section. This can lead to memory exhaustion. This is very similar to CVE-2025-64702. The difference is that this issue uses HTTP trailers, rather than HTTP headers, as the attack vector. A misbehaving or malicious peer can cause a denial-of-service (DoS) attack against quic-go's HTTP/3 servers or clients by triggering excessive memory allocation, potentially leading to crashes or resource exhaustion. This affects both servers and clients due to symmetric header construction. Version 0.59.1 enforces RFC 9114 decoded field section size limits for trailers as well. It incrementally decodes QPACK entries and checks the field section size after each entry, aborting the stream if an entry causes the limit to be exceeded.",
"title": "Description of the CVE"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "CVE-2026-40898",
"url": "https://www.suse.com/security/cve/CVE-2026-40898"
},
{
"category": "external",
"summary": "SUSE Security Ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "external",
"summary": "SUSE Bug 1271244 for CVE-2026-40898",
"url": "https://bugzilla.suse.com/1271244"
}
],
"title": "SUSE CVE CVE-2026-40898",
"tracking": {
"current_release_date": "2026-07-11T03:26:20Z",
"generator": {
"date": "2026-07-11T03:26:20Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf-vex.pl",
"version": "1"
}
},
"id": "CVE-2026-40898",
"initial_release_date": "2026-07-11T03:26:20Z",
"revision_history": [
{
"date": "2026-07-11T03:26:20Z",
"number": "2",
"summary": "vulnerabilities added,references added,severity changed from to moderate"
}
],
"status": "interim",
"version": "2"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product": {
"name": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product_identification_helper": {
"cpe": "cpe:/o:suse:packagehub:15:sp7"
}
}
},
{
"category": "product_name",
"name": "SUSE Linux Enterprise Server 16.0",
"product": {
"name": "SUSE Linux Enterprise Server 16.0",
"product_id": "SUSE Linux Enterprise Server 16.0",
"product_identification_helper": {
"cpe": "cpe:/o:suse:sles:16:16.0:server"
}
}
},
{
"category": "product_name",
"name": "SUSE Linux Enterprise Server for SAP applications 16.0",
"product": {
"name": "SUSE Linux Enterprise Server for SAP applications 16.0",
"product_id": "SUSE Linux Enterprise Server for SAP applications 16.0",
"product_identification_helper": {
"cpe": "cpe:/o:suse:sles:16:16.0:server-sap"
}
}
},
{
"category": "product_name",
"name": "SUSE Manager Client Tools for SLE 15",
"product": {
"name": "SUSE Manager Client Tools for SLE 15",
"product_id": "SUSE Manager Client Tools for SLE 15",
"product_identification_helper": {
"cpe": "cpe:/o:suse:sle-manager-tools:15"
}
}
},
{
"category": "product_name",
"name": "SUSE Multi-Linux Manager Client Tools for SLE 15",
"product": {
"name": "SUSE Multi-Linux Manager Client Tools for SLE 15",
"product_id": "SUSE Multi-Linux Manager Client Tools for SLE 15",
"product_identification_helper": {
"cpe": "cpe:/o:suse:multi-linux-managertools-sle:15"
}
}
},
{
"category": "product_name",
"name": "openSUSE Leap 16.0",
"product": {
"name": "openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0"
}
},
{
"category": "product_version",
"name": "golang-github-prometheus-prometheus",
"product": {
"name": "golang-github-prometheus-prometheus",
"product_id": "golang-github-prometheus-prometheus",
"product_identification_helper": {
"cpe": "cpe:2.3:a:prometheus:prometheus:*:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/golang-github-prometheus-prometheus@?upstream=golang-github-prometheus-prometheus.src.rpm"
}
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "golang-github-prometheus-prometheus as component of SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7:golang-github-prometheus-prometheus"
},
"product_reference": "golang-github-prometheus-prometheus",
"relates_to_product_reference": "SUSE Linux Enterprise Module for Package Hub 15 SP7"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "golang-github-prometheus-prometheus as component of SUSE Linux Enterprise Server 16.0",
"product_id": "SUSE Linux Enterprise Server 16.0:golang-github-prometheus-prometheus"
},
"product_reference": "golang-github-prometheus-prometheus",
"relates_to_product_reference": "SUSE Linux Enterprise Server 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "golang-github-prometheus-prometheus as component of SUSE Linux Enterprise Server for SAP applications 16.0",
"product_id": "SUSE Linux Enterprise Server for SAP applications 16.0:golang-github-prometheus-prometheus"
},
"product_reference": "golang-github-prometheus-prometheus",
"relates_to_product_reference": "SUSE Linux Enterprise Server for SAP applications 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "golang-github-prometheus-prometheus as component of SUSE Manager Client Tools for SLE 15",
"product_id": "SUSE Manager Client Tools for SLE 15:golang-github-prometheus-prometheus"
},
"product_reference": "golang-github-prometheus-prometheus",
"relates_to_product_reference": "SUSE Manager Client Tools for SLE 15"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "golang-github-prometheus-prometheus as component of SUSE Multi-Linux Manager Client Tools for SLE 15",
"product_id": "SUSE Multi-Linux Manager Client Tools for SLE 15:golang-github-prometheus-prometheus"
},
"product_reference": "golang-github-prometheus-prometheus",
"relates_to_product_reference": "SUSE Multi-Linux Manager Client Tools for SLE 15"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "golang-github-prometheus-prometheus as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:golang-github-prometheus-prometheus"
},
"product_reference": "golang-github-prometheus-prometheus",
"relates_to_product_reference": "openSUSE Leap 16.0"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-40898",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-40898"
}
],
"notes": [
{
"category": "general",
"text": "quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique field names and/or large values. The implementation builds an `http.Header` for the corresponding `http.Request` or `http.Response`, while only enforcing limits on the size of the QPACK-compressed HEADERS frame, not on the decoded field section. This can lead to memory exhaustion. This is very similar to CVE-2025-64702. The difference is that this issue uses HTTP trailers, rather than HTTP headers, as the attack vector. A misbehaving or malicious peer can cause a denial-of-service (DoS) attack against quic-go's HTTP/3 servers or clients by triggering excessive memory allocation, potentially leading to crashes or resource exhaustion. This affects both servers and clients due to symmetric header construction. Version 0.59.1 enforces RFC 9114 decoded field section size limits for trailers as well. It incrementally decodes QPACK entries and checks the field section size after each entry, aborting the stream if an entry causes the limit to be exceeded.",
"title": "CVE description"
}
],
"product_status": {
"known_affected": [
"SUSE Linux Enterprise Module for Package Hub 15 SP7:golang-github-prometheus-prometheus",
"SUSE Linux Enterprise Server 16.0:golang-github-prometheus-prometheus",
"SUSE Linux Enterprise Server for SAP applications 16.0:golang-github-prometheus-prometheus",
"SUSE Manager Client Tools for SLE 15:golang-github-prometheus-prometheus",
"SUSE Multi-Linux Manager Client Tools for SLE 15:golang-github-prometheus-prometheus",
"openSUSE Leap 16.0:golang-github-prometheus-prometheus"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-40898",
"url": "https://www.suse.com/security/cve/CVE-2026-40898"
},
{
"category": "external",
"summary": "SUSE Security Ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "external",
"summary": "SUSE Bug 1271244 for CVE-2026-40898",
"url": "https://bugzilla.suse.com/1271244"
}
],
"threats": [
{
"category": "impact",
"date": "2026-06-04T20:01:16Z",
"details": "moderate"
}
],
"title": "CVE-2026-40898"
}
]
}