nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Nov 27, 2018 | Nov 7, 2018 |
| Amazon_linux | — | Upgrade nginx | Dec 15, 2018 | Nov 6, 2018 |
| Debian | — | Upgrade nginx | Nov 9, 2018 | Nov 6, 2018 |
| Freebsd | — | Upgrade nginxUpgrade nginx-devel | Nov 7, 2018 | Nov 6, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade nginx | Dec 11, 2018 | Nov 7, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade nginx-all-modulesUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-mailUpgrade nginx-filesystemUpgrade nginx-mod-http-xslt-filterUpgrade nginxUpgrade nginx-mod-stream | Sep 30, 2019 | Nov 7, 2018 |
| Nginx | — | Upgrade to nginx version 1.15.6Upgrade to nginx version 1.14.1 | Nov 7, 2018 | Nov 7, 2018 |
| Suse | — | Upgrade vim-plugin-nginxUpgrade nginx-sourceUpgrade nginx | Feb 19, 2019 | Nov 6, 2018 |
| Ubuntu | — | Upgrade nginx-extrasUpgrade nginx-commonUpgrade nginx-coreUpgrade nginx-fullUpgrade nginx-light | Nov 15, 2018 | Nov 6, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 7, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub