The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1.40.0-1ubuntu0.2",
"binary_name": "libnghttp2-14"
},
{
"binary_version": "1.40.0-1ubuntu0.2",
"binary_name": "libnghttp2-dev"
},
{
"binary_version": "1.40.0-1ubuntu0.2",
"binary_name": "nghttp2"
},
{
"binary_version": "1.40.0-1ubuntu0.2",
"binary_name": "nghttp2-client"
},
{
"binary_version": "1.40.0-1ubuntu0.2",
"binary_name": "nghttp2-proxy"
},
{
"binary_version": "1.40.0-1ubuntu0.2",
"binary_name": "nghttp2-server"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "No subscription required",
"binaries": [
{
"binary_version": "9.0.31-1ubuntu0.9",
"binary_name": "libtomcat9-embed-java"
},
{
"binary_version": "9.0.31-1ubuntu0.9",
"binary_name": "libtomcat9-java"
},
{
"binary_version": "9.0.31-1ubuntu0.9",
"binary_name": "tomcat9"
},
{
"binary_version": "9.0.31-1ubuntu0.9",
"binary_name": "tomcat9-admin"
},
{
"binary_version": "9.0.31-1ubuntu0.9",
"binary_name": "tomcat9-common"
},
{
"binary_version": "9.0.31-1ubuntu0.9",
"binary_name": "tomcat9-docs"
},
{
"binary_version": "9.0.31-1ubuntu0.9",
"binary_name": "tomcat9-examples"
},
{
"binary_version": "9.0.31-1ubuntu0.9",
"binary_name": "tomcat9-user"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "No subscription required",
"binaries": [
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "aspnetcore-runtime-6.0"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "aspnetcore-targeting-pack-6.0"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "dotnet-apphost-pack-6.0"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "dotnet-host"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "dotnet-hostfxr-6.0"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "dotnet-runtime-6.0"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "dotnet-sdk-6.0"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "dotnet-sdk-6.0-source-built-artifacts"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "dotnet-targeting-pack-6.0"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "dotnet-templates-6.0"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "dotnet6"
},
{
"binary_version": "6.0.123-0ubuntu1~22.04.1",
"binary_name": "netstandard-targeting-pack-2.1"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "No subscription required",
"binaries": [
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "aspnetcore-runtime-7.0"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "aspnetcore-targeting-pack-7.0"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "dotnet-apphost-pack-7.0"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "dotnet-host-7.0"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "dotnet-hostfxr-7.0"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "dotnet-runtime-7.0"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "dotnet-sdk-7.0"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "dotnet-sdk-7.0-source-built-artifacts"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "dotnet-targeting-pack-7.0"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "dotnet-templates-7.0"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "dotnet7"
},
{
"binary_version": "7.0.112-0ubuntu1~22.04.1",
"binary_name": "netstandard-targeting-pack-2.1-7.0"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1.43.0-1ubuntu0.1",
"binary_name": "libnghttp2-14"
},
{
"binary_version": "1.43.0-1ubuntu0.1",
"binary_name": "libnghttp2-dev"
},
{
"binary_version": "1.43.0-1ubuntu0.1",
"binary_name": "nghttp2"
},
{
"binary_version": "1.43.0-1ubuntu0.1",
"binary_name": "nghttp2-client"
},
{
"binary_version": "1.43.0-1ubuntu0.1",
"binary_name": "nghttp2-proxy"
},
{
"binary_version": "1.43.0-1ubuntu0.1",
"binary_name": "nghttp2-server"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "No subscription required",
"binaries": [
{
"binary_version": "9.0.58-1ubuntu0.2",
"binary_name": "libtomcat9-embed-java"
},
{
"binary_version": "9.0.58-1ubuntu0.2",
"binary_name": "libtomcat9-java"
},
{
"binary_version": "9.0.58-1ubuntu0.2",
"binary_name": "tomcat9"
},
{
"binary_version": "9.0.58-1ubuntu0.2",
"binary_name": "tomcat9-admin"
},
{
"binary_version": "9.0.58-1ubuntu0.2",
"binary_name": "tomcat9-common"
},
{
"binary_version": "9.0.58-1ubuntu0.2",
"binary_name": "tomcat9-docs"
},
{
"binary_version": "9.0.58-1ubuntu0.2",
"binary_name": "tomcat9-examples"
},
{
"binary_version": "9.0.58-1ubuntu0.2",
"binary_name": "tomcat9-user"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "No subscription required",
"binaries": [
{
"binary_version": "8.0.0-0ubuntu1",
"binary_name": "aspnetcore-runtime-8.0"
},
{
"binary_version": "8.0.0-0ubuntu1",
"binary_name": "aspnetcore-targeting-pack-8.0"
},
{
"binary_version": "8.0.0-0ubuntu1",
"binary_name": "dotnet-apphost-pack-8.0"
},
{
"binary_version": "8.0.0-0ubuntu1",
"binary_name": "dotnet-host-8.0"
},
{
"binary_version": "8.0.0-0ubuntu1",
"binary_name": "dotnet-hostfxr-8.0"
},
{
"binary_version": "8.0.0-0ubuntu1",
"binary_name": "dotnet-runtime-8.0"
},
{
"binary_version": "8.0.100-0ubuntu1",
"binary_name": "dotnet-sdk-8.0"
},
{
"binary_version": "8.0.100-0ubuntu1",
"binary_name": "dotnet-sdk-8.0-source-built-artifacts"
},
{
"binary_version": "8.0.0-0ubuntu1",
"binary_name": "dotnet-targeting-pack-8.0"
},
{
"binary_version": "8.0.100-0ubuntu1",
"binary_name": "dotnet-templates-8.0"
},
{
"binary_version": "8.0.100-8.0.0-0ubuntu1",
"binary_name": "dotnet8"
},
{
"binary_version": "8.0.100-0ubuntu1",
"binary_name": "netstandard-targeting-pack-2.1-8.0"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1.7.1-1ubuntu0.1~esm2",
"binary_name": "libnghttp2-14"
},
{
"binary_version": "1.7.1-1ubuntu0.1~esm2",
"binary_name": "libnghttp2-dev"
},
{
"binary_version": "1.7.1-1ubuntu0.1~esm2",
"binary_name": "nghttp2"
},
{
"binary_version": "1.7.1-1ubuntu0.1~esm2",
"binary_name": "nghttp2-client"
},
{
"binary_version": "1.7.1-1ubuntu0.1~esm2",
"binary_name": "nghttp2-proxy"
},
{
"binary_version": "1.7.1-1ubuntu0.1~esm2",
"binary_name": "nghttp2-server"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1.8.8-1ubuntu0.13+esm3",
"binary_name": "haproxy"
},
{
"binary_version": "1.8.8-1ubuntu0.13+esm3",
"binary_name": "vim-haproxy"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1.30.0-1ubuntu1+esm2",
"binary_name": "libnghttp2-14"
},
{
"binary_version": "1.30.0-1ubuntu1+esm2",
"binary_name": "libnghttp2-dev"
},
{
"binary_version": "1.30.0-1ubuntu1+esm2",
"binary_name": "nghttp2"
},
{
"binary_version": "1.30.0-1ubuntu1+esm2",
"binary_name": "nghttp2-client"
},
{
"binary_version": "1.30.0-1ubuntu1+esm2",
"binary_name": "nghttp2-proxy"
},
{
"binary_version": "1.30.0-1ubuntu1+esm2",
"binary_name": "nghttp2-server"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
"binary_name": "h2o"
},
{
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
"binary_name": "libh2o-dev"
},
{
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
"binary_name": "libh2o-dev-common"
},
{
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
"binary_name": "libh2o-evloop-dev"
},
{
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
"binary_name": "libh2o-evloop0.13"
},
{
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
"binary_name": "libh2o0.13"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "8.10.0~dfsg-2ubuntu0.4+esm6",
"binary_name": "nodejs"
},
{
"binary_version": "8.10.0~dfsg-2ubuntu0.4+esm6",
"binary_name": "nodejs-dev"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4",
"binary_name": "libtomcat8-embed-java"
},
{
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4",
"binary_name": "libtomcat8-java"
},
{
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4",
"binary_name": "tomcat8"
},
{
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4",
"binary_name": "tomcat8-admin"
},
{
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4",
"binary_name": "tomcat8-common"
},
{
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4",
"binary_name": "tomcat8-docs"
},
{
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4",
"binary_name": "tomcat8-examples"
},
{
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4",
"binary_name": "tomcat8-user"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5",
"binary_name": "libtomcat9-embed-java"
},
{
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5",
"binary_name": "libtomcat9-java"
},
{
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5",
"binary_name": "tomcat9"
},
{
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5",
"binary_name": "tomcat9-admin"
},
{
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5",
"binary_name": "tomcat9-common"
},
{
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5",
"binary_name": "tomcat9-docs"
},
{
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5",
"binary_name": "tomcat9-examples"
},
{
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5",
"binary_name": "tomcat9-user"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "10.19.0~dfsg-3ubuntu1.6+esm2",
"binary_name": "libnode-dev"
},
{
"binary_version": "10.19.0~dfsg-3ubuntu1.6+esm2",
"binary_name": "libnode64"
},
{
"binary_version": "10.19.0~dfsg-3ubuntu1.6+esm2",
"binary_name": "nodejs"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "8.0.5+ds-3ubuntu0.1~esm1",
"binary_name": "trafficserver"
},
{
"binary_version": "8.0.5+ds-3ubuntu0.1~esm1",
"binary_name": "trafficserver-dev"
},
{
"binary_version": "8.0.5+ds-3ubuntu0.1~esm1",
"binary_name": "trafficserver-experimental-plugins"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "12.22.9~dfsg-1ubuntu3.6+esm2",
"binary_name": "libnode-dev"
},
{
"binary_version": "12.22.9~dfsg-1ubuntu3.6+esm2",
"binary_name": "libnode72"
},
{
"binary_version": "12.22.9~dfsg-1ubuntu3.6+esm2",
"binary_name": "nodejs"
}
]
}{
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "9.1.1+ds-2ubuntu0.1~esm1",
"binary_name": "trafficserver"
},
{
"binary_version": "9.1.1+ds-2ubuntu0.1~esm1",
"binary_name": "trafficserver-dev"
},
{
"binary_version": "9.1.1+ds-2ubuntu0.1~esm1",
"binary_name": "trafficserver-experimental-plugins"
}
]
}