UBUNTU-CVE-2026-27135

Source
https://ubuntu.com/security/CVE-2026-27135
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-27135.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-27135
Upstream
Published
2026-03-18T18:16:00Z
Modified
2026-03-25T17:36:42Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API nghttp2_session_terminate_session or nghttp2_session_terminate_session2 is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAMESIZEERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

References

Affected packages

Ubuntu:20.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2@1.40.0-1ubuntu0.3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.39.2-1
1.40.0-1
1.40.0-1build1
1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1.40.0-1ubuntu0.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.40.0-1ubuntu0.3",
            "binary_name": "libnghttp2-14"
        },
        {
            "binary_version": "1.40.0-1ubuntu0.3",
            "binary_name": "libnghttp2-dev"
        },
        {
            "binary_version": "1.40.0-1ubuntu0.3",
            "binary_name": "nghttp2"
        },
        {
            "binary_version": "1.40.0-1ubuntu0.3",
            "binary_name": "nghttp2-client"
        },
        {
            "binary_version": "1.40.0-1ubuntu0.3",
            "binary_name": "nghttp2-proxy"
        },
        {
            "binary_version": "1.40.0-1ubuntu0.3",
            "binary_name": "nghttp2-server"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-27135.json"
Ubuntu:22.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2@1.43.0-1ubuntu0.2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.43.0-1
1.43.0-1build1
1.43.0-1build2
1.43.0-1build3
1.43.0-1ubuntu0.1
1.43.0-1ubuntu0.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.43.0-1ubuntu0.2",
            "binary_name": "libnghttp2-14"
        },
        {
            "binary_version": "1.43.0-1ubuntu0.2",
            "binary_name": "libnghttp2-dev"
        },
        {
            "binary_version": "1.43.0-1ubuntu0.2",
            "binary_name": "nghttp2"
        },
        {
            "binary_version": "1.43.0-1ubuntu0.2",
            "binary_name": "nghttp2-client"
        },
        {
            "binary_version": "1.43.0-1ubuntu0.2",
            "binary_name": "nghttp2-proxy"
        },
        {
            "binary_version": "1.43.0-1ubuntu0.2",
            "binary_name": "nghttp2-server"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-27135.json"
Ubuntu:24.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2@1.59.0-1ubuntu0.2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.55.1-1
1.57.0-1
1.58.0-1
1.59.0-1
1.59.0-1build1
1.59.0-1build2
1.59.0-1build4
1.59.0-1ubuntu0.1
1.59.0-1ubuntu0.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.59.0-1ubuntu0.2",
            "binary_name": "libnghttp2-14"
        },
        {
            "binary_version": "1.59.0-1ubuntu0.2",
            "binary_name": "libnghttp2-dev"
        },
        {
            "binary_version": "1.59.0-1ubuntu0.2",
            "binary_name": "nghttp2"
        },
        {
            "binary_version": "1.59.0-1ubuntu0.2",
            "binary_name": "nghttp2-client"
        },
        {
            "binary_version": "1.59.0-1ubuntu0.2",
            "binary_name": "nghttp2-proxy"
        },
        {
            "binary_version": "1.59.0-1ubuntu0.2",
            "binary_name": "nghttp2-server"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-27135.json"
Ubuntu:25.10
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2@1.64.0-1.1ubuntu1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.64.0-1ubuntu1
1.64.0-1.1
1.64.0-1.1build1
1.64.0-1.1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.64.0-1.1ubuntu1",
            "binary_name": "libnghttp2-14"
        },
        {
            "binary_version": "1.64.0-1.1ubuntu1",
            "binary_name": "libnghttp2-dev"
        },
        {
            "binary_version": "1.64.0-1.1ubuntu1",
            "binary_name": "nghttp2"
        },
        {
            "binary_version": "1.64.0-1.1ubuntu1",
            "binary_name": "nghttp2-client"
        },
        {
            "binary_version": "1.64.0-1.1ubuntu1",
            "binary_name": "nghttp2-proxy"
        },
        {
            "binary_version": "1.64.0-1.1ubuntu1",
            "binary_name": "nghttp2-server"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-27135.json"
Ubuntu:Pro:16.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2@1.7.1-1ubuntu0.1~esm2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.6.7-1
1.*
1.3.4-2
1.4.0-1
1.4.0-2
1.5.0-2
1.6.0-1
1.7.0-1
1.7.1-1
1.7.1-1ubuntu0.1~esm1
1.7.1-1ubuntu0.1~esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.7.1-1ubuntu0.1~esm2",
            "binary_name": "libnghttp2-14"
        },
        {
            "binary_version": "1.7.1-1ubuntu0.1~esm2",
            "binary_name": "libnghttp2-dev"
        },
        {
            "binary_version": "1.7.1-1ubuntu0.1~esm2",
            "binary_name": "nghttp2"
        },
        {
            "binary_version": "1.7.1-1ubuntu0.1~esm2",
            "binary_name": "nghttp2-client"
        },
        {
            "binary_version": "1.7.1-1ubuntu0.1~esm2",
            "binary_name": "nghttp2-proxy"
        },
        {
            "binary_version": "1.7.1-1ubuntu0.1~esm2",
            "binary_name": "nghttp2-server"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-27135.json"
Ubuntu:Pro:18.04:LTS
nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2@1.30.0-1ubuntu1+esm2?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.25.0-1
1.27.0-1
1.28.0-1
1.29.0-1
1.29.0-1build1
1.30.0-1
1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm1
1.30.0-1ubuntu1+esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.30.0-1ubuntu1+esm2",
            "binary_name": "libnghttp2-14"
        },
        {
            "binary_version": "1.30.0-1ubuntu1+esm2",
            "binary_name": "libnghttp2-dev"
        },
        {
            "binary_version": "1.30.0-1ubuntu1+esm2",
            "binary_name": "nghttp2"
        },
        {
            "binary_version": "1.30.0-1ubuntu1+esm2",
            "binary_name": "nghttp2-client"
        },
        {
            "binary_version": "1.30.0-1ubuntu1+esm2",
            "binary_name": "nghttp2-proxy"
        },
        {
            "binary_version": "1.30.0-1ubuntu1+esm2",
            "binary_name": "nghttp2-server"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-27135.json"