Nghttp2 is a compact but broadly embedded HTTP/2 protocol library that sits deep in the software supply chain across servers, proxies, and client applications, making its security footprint disproportionate to its product count. Vulnerabilities affecting the library skew toward serious outcomes, with an elevated tendency to reach critical severity, acquire public exploit code, and be confirmed as exploited in the wild. The recurring weakness classes—uncontrolled resource consumption, resource allocation without throttling, improper input validation, and buffer-boundary violations—reflect the parsing and state-management complexity inherent to HTTP/2 frame processing, and a single flaw can propagate rapidly across all downstream consumers of the library. Defenders should monitor this vendor's advisories closely and prioritize remediation in internet-facing services, since patches typically require downstream rebuilds; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nghttp2 over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2024-28182MEDIUM nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATIO | Apr 4, 2024 | 5.3 | 63 | NO | NO |
CVE-2026-27135HIGH nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public | Mar 18, 2026 | 7.5 | 31 | NO | NO |
CVE-2015-8659CRITICAL The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug. | Jan 12, 2016 | 10.0 | 31 | NO | NO |
CVE-2026-58055MEDIUM nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-addi | Jun 28, 2026 | 5.4 | 29 | NO | NO |
CVE-2018-1000168HIGH nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading t | May 8, 2018 | 7.5 | 29 | NO | NO |
CVE-2023-35945HIGH Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately fo | Jul 13, 2023 | 7.5 | 21 | NO | NO |
CVE-2020-11080HIGH In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SE | Jun 3, 2020 | 7.5 | 21 | NO | NO |
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion). | Feb 6, 2020 | 3.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nghttp2.
Media articles that mention a CVE ID that affects a product developed by Nghttp2 — matched by CVE ID, not by vendor name.