Vulnerabilities > IS Http2 Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-01 | CVE-2022-25906 | OS Command Injection vulnerability in Is-Http2 Project Is-Http2 All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function. | 7.8 |