Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q678-fxj6-jj99

Опубликовано: 13 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). 

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). 

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 33%
0.00132
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
redhat
4 месяца назад

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 5.3
nvd
4 месяца назад

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость реализации протокола HTTP/2 программного обеспечения для защиты и управления трафиком приложений BIG-IP Next и программных средств BIG-IP Next SPK, BIG-IP Next CNF, BIG-IP Next for Kubernetes, BIG-IP, F5 Silverline, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 33%
0.00132
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-770