Vulnerabilities > Nghttp2 > Nghttp2 > 1.9.0

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 Resource Exhaustion vulnerability in multiple products
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
2023-07-13 CVE-2023-35945 Incomplete Cleanup vulnerability in multiple products
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy nghttp2 CWE-459
7.5
2020-06-03 CVE-2020-11080 Improper Enforcement of Message or Data Structure vulnerability in multiple products
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service.
7.5