PT-2023-12832 · Is-Http2 · Is-Http2

Published

2023-02-01

·

Updated

2025-03-26

·

CVE-2022-25906

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions is-http2 versions all
Description The issue is related to Command Injection due to missing input sanitization or other checks, and the use of sandboxes with the isH2 function.
Recommendations For all versions, consider disabling the isH2 function as a temporary workaround until a patch is available. Restrict access to the is-http2 package to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25906
GHSA-2275-RPF5-XV8H

Affected Products

Is-Http2