CVE-2018-1000168 is an Improper Input Validation vulnerability (CWE-20) in nghttp2 versions 1.10.0 through 1.31.0, specifically within its ALTSVC frame handling. This flaw can lead to a segmentation fault and subsequent denial of service (DoS) when exploited via a network client. The vulnerability is rated High severity (CVSS 7.5) due to its network-based attack vector and potential for complete service disruption. While the EPSS score is low, indicating a low probability of exploitation, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. A fix was released in nghttp2 version 1.31.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.10.0, <= 1.31.0CPE matchmatch criteria | cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:* | ||
>= 6.0.0, <= 6.8.1CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* | ||
>= 8.4.0, <= 8.17.0CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* | ||
>= 9.0.0, <= 9.11.2CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.4.1CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
May 8, 2018nghttp2: Null pointer dereference when too large ALTSVC frame is received
Apr 12, 2018