Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nghttp2

First CVE: Jan 12, 2016Active for: 11 yearsTotal CVEs: 9

Nghttp2 is a compact but broadly embedded HTTP/2 protocol library that sits deep in the software supply chain across servers, proxies, and client applications, making its security footprint disproportionate to its product count. Vulnerabilities affecting the library skew toward serious outcomes, with an elevated tendency to reach critical severity, acquire public exploit code, and be confirmed as exploited in the wild. The recurring weakness classes—uncontrolled resource consumption, resource allocation without throttling, improper input validation, and buffer-boundary violations—reflect the parsing and state-management complexity inherent to HTTP/2 frame processing, and a single flaw can propagate rapidly across all downstream consumers of the library. Defenders should monitor this vendor's advisories closely and prioritize remediation in internet-facing services, since patches typically require downstream rebuilds; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
11.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Nghttp2 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 12, 2016
10 years ago
Most Recent CVE
Jun 28, 2026
26 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2024-28182MEDIUM
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATIO
Apr 4, 20245.363NONO
CVE-2026-27135HIGH
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public
Mar 18, 20267.531NONO
CVE-2015-8659CRITICAL
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
Jan 12, 201610.031NONO
CVE-2026-58055MEDIUM
nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-addi
Jun 28, 20265.429NONO
CVE-2018-1000168HIGH
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading t
May 8, 20187.529NONO
CVE-2023-35945HIGH
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately fo
Jul 13, 20237.521NONO
CVE-2020-11080HIGH
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SE
Jun 3, 20207.521NONO
CVE-2016-1544LOW
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
Feb 6, 20203.315NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
22%
56%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
1 CVE
11.1% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nghttp2.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nghttp2 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nghttp2's Products

View all 4 CNAs →

Top CWEs