CLEANSTART-2024-ND97566

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2024/CLEANSTART-2024-ND97566.json
JSON Data
https://api.test.osv.dev/v1/vulns/CLEANSTART-2024-ND97566
Upstream
Published
2026-10-01T03:56:07Z
Modified
2026-10-01T04:15:06Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023
Details

Security vulnerability affects the nghttp2 package. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

References

Affected packages

CleanStart / nghttp2

Package

Name
nghttp2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.57.0-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2024/CLEANSTART-2024-ND97566.json"