Known vulnerabilities in nghttp2 (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:nghttp2_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 4
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting nghttp2 (Red Hat package) nghttp2 (Red Hat package) is affected by 4 known vulnerabilities: 1 high, 3 medium Critical High Medium Low

Vulnerabilities (4)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU127046 - Improper input validation
CVE-2026-27135
CWE-20 Medium
No
No
1.33.0-3.el8_2.4, 1.33.0-4.el8_4.3, 1.33.0-4.el8_6.3, 1.33.0-5.el8_8.2, 1.33.0-6.el8_10.2, 1.43.0-5.el9_0.4, 1.43.0-5.el9_2.4, 1.43.0-5.el9_4.4, 1.43.0-6.el9_6.1, 1.64.0-2.el10_1.1 23.04.2026 SB2026042395
SB20260423101
SB20260423102
and 33 more
#VU88144 - Improper input validation
CVE-2024-28182
CWE-20 Medium
No
No
1.33.0-3.el8_2.3, 1.33.0-4.el8_4.2, 1.33.0-4.el8_6.2, 1.33.0-5.el8_8.1, 1.43.0-5.el9_0.3, 1.43.0-5.el9_2.3, 1.43.0-5.el9_4.3 04.04.2024 SB2024040442
SB2024040443
SB2024040444
and 124 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
1.33.0-3.el8_1.2, 1.33.0-3.el8_2.2, 1.33.0-4.el8_4.1, 1.33.0-4.el8_6.1, 1.33.0-5.el8_8, 1.43.0-5.el9_0.2, 1.43.0-5.el9_2.1, 1.43.0-5.el9_3.1 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 652 more
#VU28538 - Resource exhaustion
CVE-2020-11080
CWE-400 Medium
No
No
1.33.0-1.el8_0.2, 1.33.0-3.el8_1.1, 1.33.0-3.el8_2.1 03.06.2020 SB2020060305
SB2020060607
SB2020060703
and 42 more