HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-43978.json"