Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xphw-4f88-5f39

Опубликовано: 14 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

EPSS

Процентиль: 45%
0.0059
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 дней назад

(When a server is configured to support unencrypted HTTP/2, it reads a ...)

CVSS3: 7.5
redhat
5 дней назад

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

CVSS3: 7.5
nvd
5 дней назад

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

CVSS3: 7.5
debian
5 дней назад

When a server is configured to support unencrypted HTTP/2, it reads a ...

EPSS

Процентиль: 45%
0.0059
Низкий

7.5 High

CVSS3

Дефекты

CWE-770