Known vulnerabilities in http2 (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:http2_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 8
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting http2 (Red Hat package) http2 (Red Hat package) is affected by 8 known vulnerabilities: 2 high, 6 medium Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU133897 - Use After Free
CVE-2026-48913
CWE-416 High
No
No
2.0.26-2.el9_4.3, 2.0.26-4.el9_6.2, 2.0.29-2.el10_0.2, 2.0.29-4.el10_2.2 08.06.2026 SB2026060493
SB20260624100
SB20260624101
and 11 more
#VU133902 - Out-of-bounds read
CVE-2026-43951
CWE-125 Medium
No
No
1.15.19-4.el9_2.8, 2.0.26-2.el9_4.3, 2.0.26-4.el9_6.2, 2.0.29-2.el10_0.2, 2.0.29-4.el10_2.2 08.06.2026 SB2026060493
SB2026062422
SB20260624100
and 21 more
#VU133362 - Resource exhaustion
CVE-2026-49975
CWE-400 High
No
No
1.15.19-4.el9_2.8, 2.0.26-2.el9_4.3, 2.0.26-4.el9_6.2, 2.0.26-6.el9_8.1, 2.0.29-2.el10_0.2 04.06.2026 SB2026060491
SB2026060492
SB2026060493
and 30 more
#VU112729 - Resource Management Errors
CVE-2025-49630
CWE-399 Medium
No
No
1.15.19-3.el9_0.7, 1.15.19-4.el9_2.7, 2.0.26-2.el9_4.2, 2.0.26-4.el9_6.1, 2.0.29-2.el10_0.1 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 27 more
#VU112727 - Resource Management Errors
CVE-2025-53020
CWE-399 Medium
No
No
1.15.19-4.el9_2.8, 2.0.26-2.el9_4.3, 2.0.26-4.el9_6.2, 2.0.29-2.el10_0.2 10.07.2025 SB2025071040
SB2025071201
SB2025071202
and 20 more
#VU93538 - NULL Pointer Dereference
CVE-2024-36387
CWE-476 Medium
No
No
2.0.26-2.el9_4.1 01.07.2024 SB2024070155
SB20240702144
SB2024070890
and 18 more
#VU88153 - Resource exhaustion
CVE-2024-27316
CWE-400 Medium
Available
No
1.15.19-3.el9_0.6, 1.15.19-4.el9_2.6, 1.15.19-5.el9_3.1 04.04.2024 SB2024040458
SB2024040502
SB2024040545
and 51 more
#VU73107 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-25690
CWE-113 Medium
Available
No
1.15.19-3.el9_0.5, 1.15.19-3.el9_1.5 07.03.2023 SB2023030731
SB2023030862
SB2023030942
and 54 more