nghttp2 records
9 published records for vendor nghttp2.
Researcher profile
- Entered KEV
- 1 · 11.1%
- Weaponized
- 1 · 11.1%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-400 Uncontrolled Resource Consumption3
- CWE-20 Improper Input Validation1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-617 Reachable Assertion1
- CWE-707 Improper Neutralization1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
46Plan | CVE-2024-28182No exploit | Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usagenghttp2 · nghttp2 · CWE-770 | Medium5.3 | — | 85.0% | Apr 4, 2024 |
41Plan | CVE-2015-8659No exploit | The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free nghttp2 · nghttp2 · CWE-119 | Critical10.0 | — | 4.0% | Jan 12, 2016 |
33Monitor | CVE-2018-1000168No exploit | nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that canghttp2 · nghttp2 · CWE-20 | High7.5 | — | 10.6% | May 8, 2018 |
32Monitor | CVE-2020-11080No exploit | Denial of service in nghttp2nghttp2 · nghttp2 · CWE-707 | High7.5 | — | 5.3% | Jun 3, 2020 |
30Monitor | CVE-2023-35945No exploit | Envoy vulnerable to HTTP/2 memory leak in nghttp2 codecenvoyproxy · envoy · CWE-400 | High7.5 | — | 1.3% | Jul 13, 2023 |
30Monitor | CVE-2026-27135No exploit | nghttp2 Denial of service: Assertion failure due to the missing state validationnghttp2 · nghttp2 · CWE-617 | High7.5 | — | 0.9% | Mar 18, 2026 |
25Monitor | CVE-2026-58055No exploit | nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Lengthnghttp2 · nghttp2 · CWE-444 | Medium6.3 | — | 0.3% | Jun 27, 2026 |
13Monitor | CVE-2016-1544No exploit | nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).nghttp2 · nghttp2 · CWE-400 | Low3.3 | — | 0.9% | Feb 6, 2020 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2024-2818246Plan
Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
MediumCVSS 5.3No exploitEPSS 85%nghttp2 · nghttp2Apr 4, 2024
- CVE-2015-865941Plan
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free
CriticalCVSS 10.0No exploitEPSS 4%nghttp2 · nghttp2Jan 12, 2016
- CVE-2018-100016833Monitor
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that ca
HighCVSS 7.5No exploitEPSS 11%nghttp2 · nghttp2May 8, 2018
- CVE-2020-1108032Monitor
Denial of service in nghttp2
HighCVSS 7.5No exploitEPSS 5%nghttp2 · nghttp2Jun 3, 2020
- CVE-2023-3594530Monitor
Envoy vulnerable to HTTP/2 memory leak in nghttp2 codec
HighCVSS 7.5No exploitEPSS 1%envoyproxy · envoyJul 13, 2023
- CVE-2026-2713530Monitor
nghttp2 Denial of service: Assertion failure due to the missing state validation
HighCVSS 7.5No exploitEPSS 1%nghttp2 · nghttp2Mar 18, 2026
- CVE-2026-5805525Monitor
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
MediumCVSS 6.3No exploitEPSS 0%nghttp2 · nghttp2Jun 27, 2026
- CVE-2016-154413Monitor
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
LowCVSS 3.3No exploitEPSS 1%nghttp2 · nghttp2Feb 6, 2020