Nghttp2
9 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Nghttp2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Nghttp2 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High4
- Medium2
- Low2
Latest CVEs
The 9 most recently published vulnerabilities affecting Nghttp2.
- CVE-2026-58055nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length5.4
- CVE-2026-27135nghttp2 Denial of service: Assertion failure due to the missing state validation7.5
- CVE-2024-28182Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage5.3
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.7.5
- CVE-2023-35945Envoy vulnerable to HTTP/2 memory leak in nghttp2 codec7.5
- CVE-2020-11080Denial of service in nghttp23.7
- CVE-2016-1544nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).3.3
- CVE-2018-1000168nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of servi...7.5
- CVE-2015-8659The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.10.0
Product grouping is registry-driven, with AI assist and human review. How it works