CVE-2018-1000168
HIGHnghttp2 <1.31.0 - DoS
Title source: llmDescription
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
References (6)
Scores
CVSS v3
7.5
EPSS
0.0336
EPSS Percentile
87.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-476
CWE-20
Status
published
Affected Products (5)
nghttp2/nghttp2
< 1.31.0
nodejs/node.js
< 6.8.1
nodejs/node.js
< 8.17.0
nodejs/node.js
< 9.11.2
debian/debian_linux
Timeline
Published
May 08, 2018
Tracked Since
Feb 18, 2026