Input validation error in nghttp2 - CVE-2026-27135
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing state validation in the nghttp2 session handling logic when processing malformed frames after session termination has been initiated. A remote attacker can send specially crafted frames to cause a denial of service.
For PRIORITY_UPDATE and ALTSVC frames, the affected extension types must be explicitly enabled. Builds with assertions disabled may not crash under the same conditions.
Affected software
Debian Linux
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nghttp2 (Ubuntu package)
nghttp2 (Red Hat package)
nghttp2
libnghttp2-devel
libnghttp2-devel-doc
libnghttp2
libnghttp2-14
nghttp2-debuginfo
nghttp2-debugsource
libnghttp2-14-debuginfo
libnghttp2-14-debuginfo-32bit
libnghttp2-14-32bit
libnghttp2-14-32bit-debuginfo
libnghttp2_asio1
libnghttp2_asio1-debuginfo
libnghttp2_asio-devel
python3-nghttp2
nghttp2-python-debugsource
python3-nghttp2-debuginfo
libnghttp2_asio1-32bit
libnghttp2_asio1-32bit-debuginfo
libnghttp2-14-64bit
libnghttp2-14-64bit-debuginfo
libnghttp2_asio1-64bit-debuginfo
libnghttp2_asio1-64bit
nghttp2-help
nghttp2 (Debian package)
nghttp2-doc
nodejs-nodemon
npm
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs
nodejs22 (Red Hat package)
nodejs24 (Red Hat package)
nodejs-packaging-bundler
nodejs-packaging
ExtremeAnalytics for Site Engine
ExtremeControl for Site Engine
ExtremeCloud IQ Site Engine
How to mitigate CVE-2026-27135
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
nghttp2 (Ubuntu package) - addressed in versions 1.7.1-1ubuntu0.1~esm3, 1.30.0-1ubuntu1+esm3, 1.40.0-1ubuntu0.3+esm1, 1.43.0-1ubuntu0.3, 1.59.0-1ubuntu0.3, 1.64.0-1.1ubuntu1.1, 1.68.0-2ubuntu0.1
nghttp2 (Red Hat package) - addressed in versions 1.33.0-3.el8_2.4, 1.33.0-4.el8_4.3, 1.33.0-4.el8_6.3, 1.33.0-5.el8_8.2, 1.33.0-6.el8_10.2, 1.43.0-5.el9_0.4, 1.43.0-5.el9_2.4, 1.43.0-5.el9_4.4, 1.43.0-6.el9_6.1, 1.64.0-2.el10_1.1
nghttp2 - addressed in versions 1.33.0-6.0.1, 1.58.0-6
libnghttp2-devel - addressed in versions 1.33.0-6.0.1, 1.58.0-6
libnghttp2-devel-doc - update to 1.33.0-6.0.1
libnghttp2 - addressed in versions 1.33.0-6.0.1, 1.58.0-6
libnghttp2-14 - addressed in versions 1.39.2-3.23.1, 1.40.0-150200.22.1, 1.40.0-150600.25.5.1, 1.64.0-150700.3.3.1
nghttp2-debuginfo - addressed in versions 1.39.2-3.23.1, 1.40.0-150200.22.1, 1.40.0-150600.25.5.1, 1.64.0-150700.3.3.1
nghttp2-debugsource - addressed in versions 1.39.2-3.23.1, 1.40.0-150200.22.1, 1.40.0-150600.25.5.1, 1.64.0-150700.3.3.1
libnghttp2-14-debuginfo - addressed in versions 1.39.2-3.23.1, 1.40.0-150200.22.1, 1.40.0-150600.25.5.1, 1.64.0-150700.3.3.1
libnghttp2-14-debuginfo-32bit - update to 1.39.2-3.23.1
libnghttp2-devel - addressed in versions 1.39.2-3.23.1, 1.40.0-150200.22.1, 1.40.0-150600.25.5.1, 1.64.0-150700.3.3.1
libnghttp2-14-32bit - addressed in versions 1.39.2-3.23.1, 1.40.0-150200.22.1, 1.40.0-150600.25.5.1, 1.64.0-150700.3.3.1
libnghttp2-14-32bit-debuginfo - addressed in versions 1.40.0-150200.22.1, 1.40.0-150600.25.5.1, 1.64.0-150700.3.3.1
libnghttp2_asio1 - addressed in versions 1.40.0-150200.22.1, 1.40.0-150600.25.5.1
libnghttp2_asio1-debuginfo - addressed in versions 1.40.0-150200.22.1, 1.40.0-150600.25.5.1
libnghttp2_asio-devel - addressed in versions 1.40.0-150200.22.1, 1.40.0-150600.25.5.1
python3-nghttp2 - update to 1.40.0-150600.25.5.1
nghttp2-python-debugsource - update to 1.40.0-150600.25.5.1
python3-nghttp2-debuginfo - update to 1.40.0-150600.25.5.1
nghttp2 - update to 1.40.0-150600.25.5.1
libnghttp2_asio1-32bit - update to 1.40.0-150600.25.5.1
libnghttp2_asio1-32bit-debuginfo - update to 1.40.0-150600.25.5.1
libnghttp2-14-64bit - update to 1.40.0-150600.25.5.1
libnghttp2-14-64bit-debuginfo - update to 1.40.0-150600.25.5.1
libnghttp2_asio1-64bit-debuginfo - update to 1.40.0-150600.25.5.1
libnghttp2_asio1-64bit - update to 1.40.0-150600.25.5.1
libnghttp2 - update to 1.41.0-7
nghttp2-debugsource - update to 1.41.0-7
nghttp2-help - update to 1.41.0-7
nghttp2 - update to 1.41.0-7
libnghttp2-devel - update to 1.41.0-7
nghttp2-debuginfo - update to 1.41.0-7
nghttp2 (Debian package) - addressed in versions 1.52.0-1+deb12u3, 1.64.0-1.1+deb13u1
nghttp2-doc - update to 1.58.0-6
nodejs-nodemon - update to 3.0.1-1
npm - update to 10.8.2-1.20.20.2.1
nodejs-docs - update to 20.20.2-1
nodejs-full-i18n - update to 20.20.2-1
nodejs-devel - update to 20.20.2-1
nodejs - update to 20.20.2-1
nodejs22 (Red Hat package) - addressed in versions 22.22.2-1.el10_1, 22.22.2-2.el10_0
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1
ExtremeAnalytics for Site Engine - update to 26.06.10
ExtremeCloud IQ Site Engine - update to 26.06.10
ExtremeControl for Site Engine - update to 26.06.10
nodejs-packaging-bundler - update to 2021.06-6
nodejs-packaging - update to 2021.06-6
External References
Related Security Bulletins
- openEuler update for nghttp2
- Input validation error in nghttp2
- Red Hat Enterprise Linux 10 update for nghttp2
- Red Hat Enterprise Linux 8 update for nghttp2
- Red Hat Enterprise Linux 9 update for the nodejs:20 module
- Red Hat Enterprise Linux 8 update for the nodejs:20 module
- Red Hat Enterprise Linux 8 update for nghttp2
- Red Hat Enterprise Linux 8 update for nghttp2
- Red Hat Enterprise Linux 8 update for nghttp2
- Red Hat Enterprise Linux 8 update for nghttp2
- Red Hat Enterprise Linux 9 update for nghttp2
- Red Hat Enterprise Linux 9 update for nghttp2
- Red Hat Enterprise Linux 9 update for nghttp2
- Red Hat Enterprise Linux 9 update for nghttp2
- Red Hat Enterprise Linux 9 update for the nodejs:20 module
- Red Hat Enterprise Linux 9 update for the nodejs:20 module
- SUSE update for nghttp2
- SUSE update for nghttp2
- SUSE update for nghttp2
- SUSE update for nghttp2
- Anolis OS update for nghttp2
- Anolis OS update for nghttp2
- Anolis OS update for nodejs:20 module
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 10 update for nodejs24
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Ubuntu update for nghttp2
- Ubuntu update for nghttp2
- Debian update for nghttp2
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Extreme Networks products update for nghttp2