CVE Vulnerabilities

CVE-2026-33814

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: May 07, 2026 | Modified: May 13, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
GoGolang*1.25.10 (excluding)
GoGolang1.26.0 (including)1.26.3 (excluding)
Http2Golang*0.53.0 (excluding)
AdsysUbuntudevel*
AdsysUbuntuesm-infra/focal*
AdsysUbuntujammy*
AdsysUbuntunoble*
AdsysUbuntuquesting*
AdsysUbunturesolute*
ContainerdUbuntuesm-apps-legacy/xenial*
ContainerdUbuntuesm-apps/bionic*
ContainerdUbuntuesm-apps/xenial*
ContainerdUbuntuesm-infra/focal*
ContainerdUbuntujammy*
Containerd-appUbuntuesm-apps/focal*
Containerd-appUbuntuesm-apps/jammy*
Containerd-appUbuntujammy*
Containerd-appUbuntunoble*
Containerd-appUbuntuquesting*
Containerd-appUbunturesolute*
Containerd-stableUbuntudevel*
Containerd-stableUbuntuquesting*
Containerd-stableUbunturesolute*
Golang-golang-x-netUbuntudevel*
Golang-golang-x-netUbuntuesm-apps/jammy*
Golang-golang-x-netUbuntuesm-apps/noble*
Golang-golang-x-netUbuntuesm-apps/resolute*
Golang-golang-x-netUbuntujammy*
Golang-golang-x-netUbuntunoble*
Golang-golang-x-netUbuntuquesting*
Golang-golang-x-netUbunturesolute*
Golang-golang-x-netUbuntuupstream*
Golang-golang-x-net-devUbuntuesm-infra/xenial*
Google-guest-agentUbuntuesm-apps/xenial*
Juju-coreUbuntuesm-infra/xenial*
LxdUbuntuesm-infra/xenial*

References