Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 37

Количество 37

ubuntu логотип

CVE-2026-27135

6 месяцев назад

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-27135

6 месяцев назад

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-27135

6 месяцев назад

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-27135

6 месяцев назад

nghttp2 Denial of service: Assertion failure due to the missing state validation

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-27135

6 месяцев назад

nghttp2 is an implementation of the Hypertext Transfer Protocol versio ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20413-1

6 месяцев назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1350-1

5 месяцев назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1247-1

5 месяцев назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1074-1

6 месяцев назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1056-1

6 месяцев назад

Security update for nghttp2

EPSS: Низкий
rocky логотип

RLSA-2026:7668

5 месяцев назад

Important: nghttp2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:7667

5 месяцев назад

Important: nghttp2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:7666

5 месяцев назад

Important: nghttp2 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7668

5 месяцев назад

ELSA-2026-7668: nghttp2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7667

5 месяцев назад

ELSA-2026-7667: nghttp2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7666

5 месяцев назад

ELSA-2026-7666: nghttp2 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:8339

5 месяцев назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2026:7896

5 месяцев назад

Important: nodejs:20 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8339

5 месяцев назад

ELSA-2026-8339: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7896

5 месяцев назад

ELSA-2026-7896: nodejs:20 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2026-27135

nghttp2 Denial of service: Assertion failure due to the missing state validation

CVSS3: 7.5
1%
Низкий
6 месяцев назад
debian логотип
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol versio ...

CVSS3: 7.5
1%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20413-1

Security update for nghttp2

1%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1350-1

Security update for nghttp2

1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1247-1

Security update for nghttp2

1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1074-1

Security update for nghttp2

1%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1056-1

Security update for nghttp2

1%
Низкий
6 месяцев назад
rocky логотип
RLSA-2026:7668

Important: nghttp2 security update

1%
Низкий
5 месяцев назад
rocky логотип
RLSA-2026:7667

Important: nghttp2 security update

1%
Низкий
5 месяцев назад
rocky логотип
RLSA-2026:7666

Important: nghttp2 security update

1%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2026-7668

ELSA-2026-7668: nghttp2 security update (IMPORTANT)

1%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2026-7667

ELSA-2026-7667: nghttp2 security update (IMPORTANT)

1%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2026-7666

ELSA-2026-7666: nghttp2 security update (IMPORTANT)

1%
Низкий
5 месяцев назад
rocky логотип
RLSA-2026:8339

Important: nodejs:20 security update

5 месяцев назад
rocky логотип
RLSA-2026:7896

Important: nodejs:20 security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-8339

ELSA-2026-8339: nodejs:20 security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-7896

ELSA-2026-7896: nodejs:20 security update (IMPORTANT)

5 месяцев назад

Уязвимостей на страницу