PT-2026-26134 · Nghttp2+3 · Nghttp2+3
Andrewmohawk
·
Publicado
2026-01-01
·
Atualizado
2026-05-06
·
CVE-2026-27135
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
nghttp2 versions prior to 1.68.1
Description
nghttp2 is a C implementation of the Hypertext Transfer Protocol version 2. Versions of nghttp2 prior to 1.68.1 are susceptible to a denial-of-service condition. This occurs because the library does not properly validate its internal state after the
nghttp2 session terminate session or nghttp2 session terminate session2 APIs are called. Consequently, the library continues to process incoming data, and a malformed frame can trigger an assertion failure, leading to a crash. The issue is triggered by receiving a frame that causes a FRAME SIZE ERROR.Recommendations
Update to nghttp2 version 1.68.1 or later.
Exploit
Correção
DoS
Assertion Failure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linuxmint
Rocky Linux
Ubuntu
Nghttp2