nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Nov 27, 2018 | Nov 7, 2018 |
| Amazon_linux | — | Upgrade nginx | Dec 15, 2018 | Nov 6, 2018 |
| Debian | — | Upgrade nginx | Nov 9, 2018 | Nov 6, 2018 |
| Freebsd | — | Upgrade nginx-develUpgrade nginx | Nov 7, 2018 | Nov 6, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade nginx | Dec 11, 2018 | Nov 7, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade nginx-mod-streamUpgrade nginx-filesystemUpgrade nginxUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-xslt-filter | Sep 30, 2019 | Nov 7, 2018 |
| Nginx | — | Upgrade to nginx version 1.15.6Upgrade to nginx version 1.14.1 | Nov 7, 2018 | Nov 7, 2018 |
| Suse | — | Upgrade vim-plugin-nginxUpgrade nginx-sourceUpgrade nginx | Feb 19, 2019 | Nov 6, 2018 |
| Ubuntu | — | Upgrade nginx-lightUpgrade nginx-coreUpgrade nginx-commonUpgrade nginx-extrasUpgrade nginx-full | Nov 15, 2018 | Nov 6, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 7, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub