Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25613
HistoryJun 05, 2020 - 3:23 a.m.

Denial Of Service (DoS)

2020-06-0503:23:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.012 Low

EPSS

Percentile

85.5%

libnghttp2.so is vulnerable to Denial Of Service (DoS). An attacker can send an overly large HTTP/2 SETTINGS frames with a length of 14,400 bytes (2400 individual settings entries) over and over again, causing 100% CPU usage and eventually crash.

References