Back

HIGH

Denial of service in nghttp2

Published Jun 3, 2020

Description

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.

Affected products

Remediation

No remediation recorded yet.

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 3, 2020
Updated Jun 9, 2025
Reserved Mar 30, 2020
CISA Vulnrichment
Updated Jun 9, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 2, 2020
ENISA EUVD
Assigner GitHub_M
Published Jun 3, 2020
Updated Jun 9, 2025
Exploited since n/a
EUVD-2020-3444