Vendor
The HTTPX2 library, prior to version 2.12.0, is vulnerable to a decompression amplification attack where malicious compressed HTTP responses can trigger large, unbonded memory allocations, leading to denial-of-service via memory exhaustion.