Записи nghttp2
9 опубликованных записей вендора nghttp2.
Профиль для исследователя
- Попали в KEV
- 1 · 11,1 %
- С эксплойтом
- 1 · 11,1 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption3
- CWE-20 Improper Input Validation1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-617 Reachable Assertion1
- CWE-707 Improper Neutralization1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
46В плане | CVE-2024-28182Эксплойта нет | Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usagenghttp2 · nghttp2 · CWE-770 | Средняя5,3 | — | 85,0 % | 4 апр. 2024 г. |
41В плане | CVE-2015-8659Эксплойта нет | The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free nghttp2 · nghttp2 · CWE-119 | Критическая10,0 | — | 4,0 % | 12 янв. 2016 г. |
33Наблюдать | CVE-2018-1000168Эксплойта нет | nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that canghttp2 · nghttp2 · CWE-20 | Высокая7,5 | — | 10,6 % | 8 мая 2018 г. |
32Наблюдать | CVE-2020-11080Эксплойта нет | Denial of service in nghttp2nghttp2 · nghttp2 · CWE-707 | Высокая7,5 | — | 5,3 % | 3 июн. 2020 г. |
30Наблюдать | CVE-2023-35945Эксплойта нет | Envoy vulnerable to HTTP/2 memory leak in nghttp2 codecenvoyproxy · envoy · CWE-400 | Высокая7,5 | — | 1,3 % | 13 июл. 2023 г. |
30Наблюдать | CVE-2026-27135Эксплойта нет | nghttp2 Denial of service: Assertion failure due to the missing state validationnghttp2 · nghttp2 · CWE-617 | Высокая7,5 | — | 0,9 % | 18 мар. 2026 г. |
25Наблюдать | CVE-2026-58055Эксплойта нет | nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Lengthnghttp2 · nghttp2 · CWE-444 | Средняя6,3 | — | 0,3 % | 27 июн. 2026 г. |
13Наблюдать | CVE-2016-1544Эксплойта нет | nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).nghttp2 · nghttp2 · CWE-400 | Низкая3,3 | — | 0,9 % | 6 февр. 2020 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2024-2818246В плане
Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
СредняяCVSS 5,3Эксплойта нетEPSS 85 %nghttp2 · nghttp24 апр. 2024 г.
- CVE-2015-865941В плане
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %nghttp2 · nghttp212 янв. 2016 г.
- CVE-2018-100016833Наблюдать
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that ca
ВысокаяCVSS 7,5Эксплойта нетEPSS 11 %nghttp2 · nghttp28 мая 2018 г.
- CVE-2020-1108032Наблюдать
Denial of service in nghttp2
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %nghttp2 · nghttp23 июн. 2020 г.
- CVE-2023-3594530Наблюдать
Envoy vulnerable to HTTP/2 memory leak in nghttp2 codec
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %envoyproxy · envoy13 июл. 2023 г.
- CVE-2026-2713530Наблюдать
nghttp2 Denial of service: Assertion failure due to the missing state validation
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %nghttp2 · nghttp218 мар. 2026 г.
- CVE-2026-5805525Наблюдать
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
СредняяCVSS 6,3Эксплойта нетEPSS 0 %nghttp2 · nghttp227 июн. 2026 г.
- CVE-2016-154413Наблюдать
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
НизкаяCVSS 3,3Эксплойта нетEPSS 1 %nghttp2 · nghttp26 февр. 2020 г.