A denial-of-service vulnerability exists in the way Kestrel parses HTTP/2 requests. The security update addresses the vulnerability by fixing the way the Kestrel parses HTTP/2 requests. Users are advised to upgrade.
{
"nvd_published_at": "2021-01-12T20:15:00Z",
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed_at": "2022-10-24T20:26:09Z",
"github_reviewed": true
}