Nghttp2
1 CVEs tracked since 2016. Since Jan 2016, none of them reached CISA KEV.
Nghttp2 CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2016-01 | 1 | 0 |
Products
The products that kept showing up in Nghttp2's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 9 most recently published vulnerabilities affecting Nghttp2.
- CVE-2026-58055nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length5.4
- CVE-2026-27135nghttp2 Denial of service: Assertion failure due to the missing state validation7.5
- CVE-2024-28182Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage5.3
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.7.5
- CVE-2023-35945Envoy vulnerable to HTTP/2 memory leak in nghttp2 codec7.5
- CVE-2020-11080Denial of service in nghttp23.7
- CVE-2016-1544nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).3.3
- CVE-2018-1000168nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of servi...7.5
- CVE-2015-8659The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.10.0
The record
- Peak rank
- #110 in Jan 2016
- Busiest month shown
- Jan 2016, 1 CVEs
- Months with a KEV entry
- 0 since Jan 2016
- Monthly snapshots
- 1 since 2016