CRITICAL10.0CVE-2015-8659The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free… from 0, < 1.6.0-1
HIGH7.5CVE-2026-27135nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. from 0, < 1.43.0-1+deb11u3
HIGH7.5Denial of service in nghttp2
from 0, < 1.41.0-1
HIGH7.5Denial of service in nghttp2
from 0, < 1.36.0-2+deb10u2
HIGH7.5nghttp2 - security update
from 0, < 1.31.1-1
HIGH7.5nghttp2 - security update
from 0, < 1.18.1-1+deb9u2
MEDIUM5.3nghttp2 - security update
from 0, < 1.43.0-1+deb11u2
MEDIUM5.3nghttp2 - security update
from 0, < 1.36.0-2+deb10u3
MEDIUM5.3nghttp2 - security update
from 0, < 1.43.0-1+deb11u2
LOW3.3nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
from 0, < 1.7.1-1
—nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusabl…
from 0