← Vulnerability feed

Vulnerability record · CVE-2026-27135 · published 18 March 2026

CVE-2026-27135: Nghttp2 vulnerability

Nghttp2 · Nghttp2

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

7.5 CVSS 3.1 High EPSS 0.89% · top 42.2% CWE-617 · CWE-617
7.5CVSS 3.1 base score
0.89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
55References
15 Jul 2026Last modified by NVD

Description

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1 Patch
https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 PatchVendor Advisory
http://www.openwall.com/lists/oss-security/2026/03/20/3 Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2026/05/msg00025.html
https://access.redhat.com/errata/RHSA-2026:10065
https://access.redhat.com/errata/RHSA-2026:11768
https://access.redhat.com/errata/RHSA-2026:13812
https://access.redhat.com/errata/RHSA-2026:14773
https://access.redhat.com/errata/RHSA-2026:14937
https://access.redhat.com/errata/RHSA-2026:15087
https://access.redhat.com/errata/RHSA-2026:16008
https://access.redhat.com/errata/RHSA-2026:16009
https://access.redhat.com/errata/RHSA-2026:16030
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:17596
https://access.redhat.com/errata/RHSA-2026:19724
https://access.redhat.com/errata/RHSA-2026:19725
https://access.redhat.com/errata/RHSA-2026:20040
https://access.redhat.com/errata/RHSA-2026:20087
https://access.redhat.com/errata/RHSA-2026:21656
https://access.redhat.com/errata/RHSA-2026:21690
https://access.redhat.com/errata/RHSA-2026:21695
https://access.redhat.com/errata/RHSA-2026:25096
https://access.redhat.com/errata/RHSA-2026:27200
https://access.redhat.com/errata/RHSA-2026:27201
https://access.redhat.com/errata/RHSA-2026:6190
https://access.redhat.com/errata/RHSA-2026:7080
https://access.redhat.com/errata/RHSA-2026:7123
https://access.redhat.com/errata/RHSA-2026:7302
https://access.redhat.com/errata/RHSA-2026:7310
https://access.redhat.com/errata/RHSA-2026:7350
https://access.redhat.com/errata/RHSA-2026:7666
https://access.redhat.com/errata/RHSA-2026:7667
https://access.redhat.com/errata/RHSA-2026:7668
https://access.redhat.com/errata/RHSA-2026:7670
https://access.redhat.com/errata/RHSA-2026:7675
https://access.redhat.com/errata/RHSA-2026:7896
https://access.redhat.com/errata/RHSA-2026:7983
https://access.redhat.com/errata/RHSA-2026:8339
https://access.redhat.com/errata/RHSA-2026:8538

Track CVE-2026-27135 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed10.0CVE-2015-8659Apple mac os x memory buffer overflow vulnerabilityThe idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.EPSS 4.0%7.5CVE-2023-35945Envoyproxy envoy uncontrolled resource consumption vulnerabilityEnvoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiv…EPSS 1.3%7.5CVE-2020-11080Nghttp2 uncontrolled resource consumption vulnerabilityIn nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a mal…EPSS 5.3%7.5CVE-2018-1000168Nghttp2 improper input validation vulnerabilitynghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result …EPSS 11%6.3CVE-2026-58055Nghttp2 http request smuggling vulnerabilitynghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-ali…EPSS 0.32%5.3CVE-2024-28182nghttp2 HTTP/2 CONTINUATION frame flood causes CPU exhaustionnghttp2 before 1.61.0 keeps reading an unbounded number of HTTP/2 CONTINUATION frames after a stream is reset, in order to keep the HPACK context in …EPSS 85%analysed3.3CVE-2016-1544Nghttp2 uncontrolled resource consumption vulnerabilitynghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2026-27135), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.