Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-1000168


nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.


Published

2018-05-08T15:29:00.207

Last Modified

2025-06-09T16:15:27.577

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20
    CWE-476
  • Type: Secondary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nghttp2 nghttp2 ≤ 1.31.0 Yes
Application nodejs node.js ≤ 6.8.1 Yes
Application nodejs node.js ≤ 8.17.0 Yes
Application nodejs node.js ≤ 9.11.2 Yes
Application nodejs node.js < 10.4.1 Yes
Operating System debian debian_linux 9.0 Yes

References