Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27141

Опубликовано: 26 фев. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

A flaw was found in golang.org/x/net/http2. A remote attacker can exploit this vulnerability by sending specially crafted HTTP/2 frames, which are data packets used in the HTTP/2 protocol. Due to a missing check for null values, processing these specific frames (types 0x0a through 0x0f) can cause the server to crash. This leads to a Denial of Service (DoS) condition, making the affected server unavailable to legitimate users.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Under investigation
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Under investigation
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Under investigation
Compliance Operatorcompliance/openshift-compliance-operator-bundleUnder investigation
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorUnder investigation
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Under investigation
Cryostat 4cryostat/cryostat-storage-rhel9Under investigation
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Under investigation
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorUnder investigation
ExternalDNS Operatoredo/external-dns-rhel8Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2443104golang.org/x/net/http2: golang.org/x/net/http2: Denial of Service due to malformed HTTP/2 frames

EPSS

Процентиль: 5%
0.0002
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
28 дней назад

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

CVSS3: 7.5
nvd
28 дней назад

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

CVSS3: 7.5
msrc
22 дня назад

Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net

CVSS3: 7.5
debian
28 дней назад

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a ...

CVSS3: 7.5
github
28 дней назад

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

EPSS

Процентиль: 5%
0.0002
Низкий

5.3 Medium

CVSS3