Skip to content
Noroxi

nghttp2 records

9 published records for vendor nghttp2.

Researcher profile

Entered KEV
1 · 11.1%
Weaponized
1 · 11.1%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
0 days

All records

9 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage

    MediumCVSS 5.3No exploitEPSS 85%

    nghttp2 · nghttp2Apr 4, 2024

  • The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free

    CriticalCVSS 10.0No exploitEPSS 4%

    nghttp2 · nghttp2Jan 12, 2016

  • nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that ca

    HighCVSS 7.5No exploitEPSS 11%

    nghttp2 · nghttp2May 8, 2018

  • Denial of service in nghttp2

    HighCVSS 7.5No exploitEPSS 5%

    nghttp2 · nghttp2Jun 3, 2020

  • Envoy vulnerable to HTTP/2 memory leak in nghttp2 codec

    HighCVSS 7.5No exploitEPSS 1%

    envoyproxy · envoyJul 13, 2023

  • nghttp2 Denial of service: Assertion failure due to the missing state validation

    HighCVSS 7.5No exploitEPSS 1%

    nghttp2 · nghttp2Mar 18, 2026

  • nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length

    MediumCVSS 6.3No exploitEPSS 0%

    nghttp2 · nghttp2Jun 27, 2026

  • CVE-2016-1544
    13Monitor

    nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).

    LowCVSS 3.3No exploitEPSS 1%

    nghttp2 · nghttp2Feb 6, 2020