CVE-2018-16843
CVSS v3.1
7.5 (High)
CVSS v2.0
7.8 (High)
EPSS
10.85 % (95th)
Affected Products
5
Advisories
12
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Weaknesses
- CWE-400
- Uncontrolled Resource Consumption
- CVE Status
- PUBLISHED
- CNA
- Red Hat, Inc.
- Published Date
-
2018-11-07 14:29:00
(5 years ago) - Updated Date
-
2022-02-22 19:27:12
(2 years ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Configuration #2
|
Configuration #3
|
Configuration #4
|
Configuration #5
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...