Skip to content

[Security] Vulnerability found in Security vulnerability CVE-2023-44487 in package nghttp2 #93

@sajjaphani

Description

@sajjaphani

Security Vulnerability Alert

Package: nghttp2 v1.51.0

Vulnerability ID: CVE-2023-44487
Source: National Vulnerability Database (NVD)
Severity: HIGH
Score: 7.5

Summary

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

References

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions