What is CVE-2026-56853?
CVE-2026-56853 is a vulnerability where servers configured for unencrypted HTTP/2 fail to apply the ReadHeaderTimeout setting when reading initial bytes for the client preface. This can lead to resource exhaustion attacks, such as slowloris. Affected servers should update their configuration or disable unencrypted HTTP/2 support.
Azərbaycanca: CVE-2026-56853 şifrələnməmiş HTTP/2 dəstəkləyən serverlərdə yeni bağlantıların ilk baytlarını oxuyarkən ReadHeaderTimeout parametrinin tətbiq edilməməsi zəifliyidir. Bu, resurs tükənməsi (məsələn, slowloris hücumları) riski yaradır. Təsirə məruz qalan serverlərdə konfiqurasiya yenilənməli və ya şifrələnməmiş HTTP/2 dəstəyi deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What type of attacks can be carried out exploiting CVE-2026-56853?
Resource exhaustion attacks, such as slowloris, can be carried out.
What measure should be taken to mitigate CVE-2026-56853?
The server configuration should be updated or unencrypted HTTP/2 support should be disabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.