Known vulnerabilities in mod_http2 (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:mod_http2_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 6
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting mod_http2 (Red Hat package) mod_http2 (Red Hat package) is affected by 6 known vulnerabilities: 1 high, 5 medium Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU88153 - Resource exhaustion
CVE-2024-27316
CWE-400 Medium
Available
No
2.0.26-2.el9_4 04.04.2024 SB2024040458
SB2024040502
SB2024040545
and 51 more
#VU82247 - Resource Management Errors
CVE-2023-43622
CWE-399 Medium
Available
No
2.0.26-1.el9 19.10.2023 SB2023101942
SB2023101960
SB2023102647
and 11 more
#VU82245 - Resource Management Errors
CVE-2023-45802
CWE-399 Medium
No
No
2.0.26-1.el9 19.10.2023 SB2023101942
SB2023101960
SB2023102104
and 37 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
2.0.26-1.el9 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 652 more
#VU73107 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-25690
CWE-113 Medium
Available
No
1.15.19-5.el9 07.03.2023 SB2023030731
SB2023030862
SB2023030942
and 54 more
#VU73106 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-27522
CWE-113 Medium
No
No
1.15.19-5.el9 07.03.2023 SB2023030731
SB2023030862
SB2023030942
and 33 more