The vulnerability exists due to improper memory boundary checks within the newly optimized HTTP/2 state tracker. When handling highly fragmented or out-of-order network traffic, the parser fails to properly calculate segment offsets, leading to a heap-based out-of-bounds read and an engine crash.