MidnightBSD

Advisories for nghttp2

CVE-2015-8659 HIGH

The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
apple watchos *
nghttp2 nghttp2 *
apple tvos *
apple iphone_os *
apple mac_os_x *
CVE-2016-1544 LOW

nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 3.3 LOW CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L 1.8 1.4

CVSS 2.0

Severity: LOW

Problem Type: CWE-400,

Products Affected

Vendor Product Version
fedoraproject fedora 23
nghttp2 nghttp2 *
fedoraproject fedora 22
CVE-2018-1000168 MEDIUM

nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,CWE-476,CWE-476,

Products Affected

Vendor Product Version
nghttp2 nghttp2 *
nodejs node.js *
debian debian_linux 9.0
CVE-2020-11080 MEDIUM

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security-advisories@github.com 3.7 LOW CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L 2.2 1.4
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-707,CWE-400,

Products Affected

Vendor Product Version
oracle enterprise_communications_broker 3.1.0
oracle banking_extensibility_workbench 14.4.0
fedoraproject fedora 31
nghttp2 nghttp2 *
debian debian_linux 10.0
oracle enterprise_communications_broker 3.2.0
oracle mysql *
opensuse leap 15.1
oracle graalvm 19.3.2
oracle graalvm 20.1.0
nodejs node.js *
fedoraproject fedora 33
oracle blockchain_platform *
debian debian_linux 9.0
oracle banking_extensibility_workbench 14.3.0
CVE-2023-35945

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the `GOAWAY` frame skips de-allocation of the bookkeeping structure and pending compressed header. The error return [code path] is taken if connection is already marked for not sending more requests due to `GOAWAY` frame. The clean-up code is right after the return statement, causing memory leak. Denial of service through memory exhaustion. This vulnerability was patched in versions(s) 1.26.3, 1.25.8, 1.24.9, 1.23.11.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security-advisories@github.com 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
envoyproxy envoy *
nghttp2 nghttp2 *
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
redhat jboss_core_services -
f5 nginx_plus r30
cisco secure_web_appliance_firmware *
microsoft visual_studio_2022 *
f5 nginx_plus r29
cisco enterprise_chat_and_email -
redhat self_node_remediation_operator -
redhat web_terminal -
redhat fence_agents_remediation_operator -
f5 big-ip_local_traffic_manager *
f5 big-ip_global_traffic_manager *
redhat openstack_platform 17.1
envoyproxy envoy 1.25.9
f5 big-ip_local_traffic_manager 17.1.0
redhat build_of_quarkus -
eclipse jetty *
redhat advanced_cluster_security 4.0
microsoft windows_10_22h2 *
redhat enterprise_linux 8.0
cisco iot_field_network_director *
redhat openshift_service_mesh 2.0
redhat jboss_a-mq 7
linkerd linkerd 2.14.1
f5 big-ip_link_controller *
microsoft windows_11_22h2 *
cisco fog_director *
redhat openshift_gitops -
debian debian_linux 12.0
f5 big-ip_fraud_protection_service *
cisco prime_cable_provisioning *
microsoft windows_10_1809 *
cisco data_center_network_manager -
apache solr *
cisco secure_dynamic_attributes_connector *
redhat openshift_container_platform 4.0
redhat node_healthcheck_operator -
redhat certification_for_red_hat_enterprise_linux 8.0
istio istio *
caddyserver caddy *
apache tomcat 11.0.0
grpc grpc 1.57.0
microsoft windows_server_2019 -
f5 big-ip_policy_enforcement_manager *
redhat migration_toolkit_for_virtualization -
redhat openshift_container_platform_assisted_installer -
microsoft windows_10_1607 *
redhat service_interconnect 1.0
f5 big-ip_global_traffic_manager 17.1.0
amazon opensearch_data_prepper *
redhat openshift_api_for_data_protection -
redhat network_observability_operator -
redhat enterprise_linux 9.0
f5 big-ip_analytics 17.1.0
redhat satellite 6.0
f5 big-ip_ssl_orchestrator 17.1.0
cisco firepower_threat_defense *
cisco telepresence_video_communication_server *
microsoft .net *
f5 big-ip_application_acceleration_manager 17.1.0
redhat machine_deletion_remediation_operator -
cisco ultra_cloud_core_-_policy_control_function 2024.01.0
redhat advanced_cluster_management_for_kubernetes 2.0
redhat node_maintenance_operator -
f5 big-ip_websafe 17.1.0
cisco unified_contact_center_management_portal -
redhat decision_manager 7.0
microsoft windows_10_21h2 *
redhat advanced_cluster_security 3.0
golang http2 *
redhat jboss_fuse 6.0.0
redhat openshift_data_science -
apache traffic_server *
envoyproxy envoy 1.27.0
f5 nginx *
jenkins jenkins *
cisco crosswork_zero_touch_provisioning *
kazu-yamamoto http2 *
cisco unified_attendant_console_advanced -
linkerd linkerd 2.14.0
redhat openshift_developer_tools_and_services -
microsoft asp.net_core *
cisco ultra_cloud_core_-_policy_control_function *
netapp oncommand_insight -
fedoraproject fedora 38
redhat openshift_pipelines -
f5 big-ip_carrier-grade_nat *
f5 big-ip_websafe *
redhat openshift_sandboxed_containers -
redhat migration_toolkit_for_containers -
netapp astra_control_center -
redhat openstack_platform 16.2
redhat integration_camel_k -
redhat openshift -
f5 big-ip_ddos_hybrid_defender *
f5 big-ip_advanced_firewall_manager *
openresty openresty *
f5 big-ip_fraud_protection_service 17.1.0
fedoraproject fedora 37
f5 big-ip_policy_enforcement_manager 17.1.0
linkerd linkerd 2.13.1
microsoft windows_server_2016 -
redhat ansible_automation_platform 2.0
cisco prime_infrastructure *
f5 big-ip_application_visibility_and_reporting *
debian debian_linux 11.0
f5 big-ip_application_visibility_and_reporting 17.1.0
redhat service_telemetry_framework 1.5
cisco ultra_cloud_core_-_serving_gateway_function *
projectcontour contour *
f5 big-ip_webaccelerator 17.1.0
cisco crosswork_situation_manager -
konghq kong_gateway *
apple swiftnio_http/2 *
redhat support_for_spring_boot -
netty netty *
varnish_cache_project varnish_cache *
redhat jboss_enterprise_application_platform 6.0.0
cisco prime_access_registrar *
f5 big-ip_advanced_firewall_manager 17.1.0
redhat build_of_optaplanner 8.0
facebook proxygen *
redhat cost_management -
redhat quay 3.0.0
f5 big-ip_advanced_web_application_firewall 17.1.0
redhat openshift_serverless -
redhat migration_toolkit_for_applications 6.0
ietf http 2.0
redhat openshift_virtualization 4
f5 big-ip_ssl_orchestrator *
redhat ceph_storage 5.0
f5 nginx_ingress_controller *
f5 big-ip_next_service_proxy_for_kubernetes *
linecorp armeria *
cisco ios_xe *
redhat openshift_distributed_tracing -
f5 nginx_plus *
redhat cert-manager_operator_for_red_hat_openshift -
redhat openshift_secondary_scheduler_operator -
linkerd linkerd 2.13.0
redhat 3scale_api_management_platform 2.0
cisco secure_malware_analytics *
traefik traefik *
cisco unified_contact_center_enterprise_-_live_data_server *
redhat jboss_data_grid 7.0.0
redhat jboss_fuse 7.0.0
redhat integration_service_registry -
cisco crosswork_data_gateway 5.0
f5 big-ip_webaccelerator *
f5 big-ip_analytics *
apache apisix *
redhat integration_camel_for_spring_boot -
nghttp2 nghttp2 *
envoyproxy envoy 1.26.4
cisco connected_mobile_experiences *
apache tomcat *
cisco unified_contact_center_enterprise -
golang networking *
cisco nx-os *
f5 big-ip_next 20.0.1
f5 big-ip_ddos_hybrid_defender 17.1.0
f5 big-ip_domain_name_system 17.1.0
grpc grpc *
f5 big-ip_access_policy_manager *
traefik traefik 3.0.0
cisco prime_network_registrar *
cisco expressway *
dena h2o *
redhat jboss_a-mq_streams -
redhat cryostat 2.0
cisco business_process_automation *
redhat openshift_dev_spaces -
microsoft windows_11_21h2 *
envoyproxy envoy 1.24.10
microsoft azure_kubernetes_service *
f5 big-ip_domain_name_system *
f5 big-ip_access_policy_manager 17.1.0
redhat certification_for_red_hat_enterprise_linux 9.0
f5 big-ip_advanced_web_application_firewall *
cisco unified_contact_center_domain_manager -
redhat jboss_enterprise_application_platform 7.0.0
f5 big-ip_carrier-grade_nat 17.1.0
cisco ios_xr *
nodejs node.js *
f5 big-ip_application_acceleration_manager *
linkerd linkerd *
redhat process_automation 7.0
redhat enterprise_linux 6.0
redhat openstack_platform 16.1
redhat single_sign-on 7.0
debian debian_linux 10.0
redhat run_once_duration_override_operator -
golang go *
cisco ultra_cloud_core_-_session_management_function *
microsoft cbl-mariner *
redhat logging_subsystem_for_red_hat_openshift -
f5 big-ip_application_security_manager 17.1.0
f5 big-ip_link_controller 17.1.0
microsoft windows_server_2022 -
cisco crosswork_data_gateway *
akka http_server *
f5 big-ip_application_security_manager *
CVE-2024-28182

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security-advisories@github.com 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L 3.9 1.4

Products Affected

Vendor Product Version
debian debian_linux 11.0
fedoraproject fedora 39
fedoraproject fedora 40
fedoraproject fedora 38
nghttp2 nghttp2 *
debian debian_linux 10.0
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
security-advisories@github.com 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
nghttp2 nghttp2 *