Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.36% | — | Perl Protocol Http2AI | 7/9/2026 | 8/9/2026 | Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream reaches the CLOSED state, stream_state returns the concurrency slot and clears most of the stream's keys, but the entry itself stays in the connection… | |
| Analizada | Media (6.3) | 0.32% | — | Nghttp2 | 28/6/2026 | 30/6/2026 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the… | |
| Modificada | Alta (7.5) | 0.78% | — | Golang GOGolang Http2 | 7/5/2026 | 18/9/2026 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. | |
| Modificada | Alta (7.5) | 0.89% | — | Nghttp2 | 18/3/2026 | 15/7/2026 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called… | |
| Aplazada | Baja (3.7) | 0.29% | — | Nghttp2AIPowerdns DnsdistAI | 18/9/2025 | 17/6/2026 | In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources. | |
| Aplazada | Alta (7.5) | 2.3% | — | Nghttp2AIH2OAIPowerdns DnsdistAI | 29/4/2025 | 17/6/2026 | When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.9 version. A workaround is to… | |
| Aplazada | Alta (8.2) | 87% | — | NodejsAINghttp2AI | 9/4/2024 | 17/6/2026 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is… | |
| Modificada | Media (5.3) | 85% | — | Nghttp2Debian LinuxFedoraproject Fedora | 4/4/2024 | 17/6/2026 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2… | |
| Modificada | Alta (7.5) | 3.8% | — | Golang GOGolang Http2Fedoraproject FedoraNetapp Astra Trident+1 | 11/10/2023 | 17/6/2026 | A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.5) | 1.3% | — | Envoyproxy EnvoyNghttp2 | 13/7/2023 | 17/6/2026 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the `GOAWAY` frame skips… | |
| Modificada | Alta (7.5) | 4.6% | — | Golang GOGolang HpackGolang Http2 | 28/2/2023 | 17/6/2026 | A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests. | |
| Modificada | Alta (7.8) | 1.1% | — | Is-http2 Project Is-http2 | 1/2/2023 | 17/6/2026 | All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function. | |
| Modificada | Media (5.3) | 5.8% | — | Golang GOGolang Http2Fedoraproject Fedora | 8/12/2022 | 17/6/2026 | An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB… | |
| Modificada | Alta (7.5) | 5.3% | — | Nghttp2Debian LinuxOpensuse LeapFedoraproject Fedora+6 | 3/6/2020 | 17/6/2026 | In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at… | |
| Modificada | Baja (3.3) | 0.89% | — | Nghttp2Fedoraproject Fedora | 6/2/2020 | 17/6/2026 | nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion). | |
| Modificada | Alta (7.5) | 11% | — | Nghttp2Nodejs Node.jsDebian Linux | 8/5/2018 | 17/6/2026 | nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1. | |
| Modificada | Crítica (10) | 4.0% | — | Apple MAC OS XNghttp2Apple Iphone OSApple Tvos+1 | 12/1/2016 | 17/6/2026 | The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug. |