Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 32

Количество 32

ubuntu логотип

CVE-2026-27135

4 месяца назад

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-27135

4 месяца назад

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-27135

4 месяца назад

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-27135

4 месяца назад

nghttp2 Denial of service: Assertion failure due to the missing state validation

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-27135

4 месяца назад

nghttp2 is an implementation of the Hypertext Transfer Protocol versio ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20413-1

4 месяца назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1350-1

4 месяца назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1247-1

4 месяца назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1074-1

4 месяца назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1056-1

4 месяца назад

Security update for nghttp2

EPSS: Низкий
rocky логотип

RLSA-2026:7668

4 месяца назад

Important: nghttp2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:7667

4 месяца назад

Important: nghttp2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:7666

4 месяца назад

Important: nghttp2 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7668

4 месяца назад

ELSA-2026-7668: nghttp2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7667

4 месяца назад

ELSA-2026-7667: nghttp2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7666

4 месяца назад

ELSA-2026-7666: nghttp2 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:8339

4 месяца назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2026:7896

4 месяца назад

Important: nodejs:20 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8339

4 месяца назад

ELSA-2026-8339: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7896

4 месяца назад

ELSA-2026-7896: nodejs:20 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-27135

nghttp2 Denial of service: Assertion failure due to the missing state validation

CVSS3: 7.5
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol versio ...

CVSS3: 7.5
1%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20413-1

Security update for nghttp2

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1350-1

Security update for nghttp2

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1247-1

Security update for nghttp2

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1074-1

Security update for nghttp2

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1056-1

Security update for nghttp2

1%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:7668

Important: nghttp2 security update

1%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:7667

Important: nghttp2 security update

1%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:7666

Important: nghttp2 security update

1%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-7668

ELSA-2026-7668: nghttp2 security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2026-7667

ELSA-2026-7667: nghttp2 security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2026-7666

ELSA-2026-7666: nghttp2 security update (IMPORTANT)

4 месяца назад
rocky логотип
RLSA-2026:8339

Important: nodejs:20 security update

4 месяца назад
rocky логотип
RLSA-2026:7896

Important: nodejs:20 security update

4 месяца назад
oracle-oval логотип
ELSA-2026-8339

ELSA-2026-8339: nodejs:20 security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2026-7896

ELSA-2026-7896: nodejs:20 security update (IMPORTANT)

4 месяца назад

Уязвимостей на страницу