CVE-2020-11080
published 2020-06-03CVE-2020-11080: In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.32%
91.7th percentile
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nghttp2 | < nghttp2 1.41.0-1 (bookworm) | nghttp2 1.41.0-1 (bookworm) |
| debian | nodejs | < nghttp2 1.41.0-1 (bookworm) | nghttp2 1.41.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_nghttp2_1.41.0-1_on_cbl_mariner_1.0 | — | — |
| nghttp2 | nghttp2 | < 1.41.0 | 1.41.0 |
| nghttp2 | nghttp2 | >= 0 < 1.41.0-1 | 1.41.0-1 |
| nghttp2 | nghttp2 | >= 0 < 1.41.0-1 | 1.41.0-1 |
| nghttp2 | nghttp2 | >= 0 < 1.41.0-1 | 1.41.0-1 |
| nghttp2 | nghttp2 | >= 0 < 1.41.0-1 | 1.41.0-1 |
| nodejs | node.js | 10.0.0 – 10.12.0 | — |
| nodejs | node.js | >= 10.13.0 < 10.21.0 | 10.21.0 |
| nodejs | node.js | 12.0.0 – 12.12.0 | — |
| nodejs | node.js | >= 12.13.0 < 12.18.0 | 12.18.0 |
| nodejs | node.js | 14.0.0 – 14.4.0 | — |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| opensuse | leap | — | — |
| oracle | banking_extensibility_workbench | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nghttp2 vulnerability
vendor_ubuntu·2023-06-06
CVE-2020-11080 nghttp2 vulnerability
Title: nghttp2 vulnerability
Summary: nghttp2 could be made to crash if it opened a specially crafted file.
Gal Goldshtein discovered that nghttp2 incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Hitachi Energy e-mesh EMS
cisa_ics·2022-03-31·CVSS 8.1
[HIGH] Hitachi Energy e-mesh EMS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy e-mesh EMS
Last RevisedMarch 31, 2022
Alert CodeICSA-22-090-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: e-mesh EMS
- Vulnerabilities: Improper Restriction of Operations Within the Bounds of a Memory Buffer, Use After Free, Uncontrolled Resource Consumption
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following version of e-mesh EMS, an optimizer
Oracle
Oracle Oracle Communications Risk Matrix: System (nghttp2) — CVE-2020-11080
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2020-11080 [LOW] Oracle Oracle Communications Risk Matrix: System (nghttp2) — CVE-2020-11080
Oracle Oracle Communications Risk Matrix: System (nghttp2) vulnerability
CVE: CVE-2020-11080
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: System (http2) — CVE-2020-11080
vendor_oracle·2020-10-15·CVSS 7.5
CVE-2020-11080 [LOW] Oracle Oracle Communications Risk Matrix: System (http2) — CVE-2020-11080
Oracle Oracle Communications Risk Matrix: System (http2) vulnerability
CVE: CVE-2020-11080
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle GraalVM Risk Matrix: JavaScript (Node.js) — CVE-2020-11080
vendor_oracle·2020-07-15·CVSS 7.5
CVE-2020-11080 [LOW] Oracle Oracle GraalVM Risk Matrix: JavaScript (Node.js) — CVE-2020-11080
Oracle Oracle GraalVM Risk Matrix: JavaScript (Node.js) vulnerability
CVE: CVE-2020-11080
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Microsoft
Denial of service in nghttp2
vendor_msrc·2020-06-09·CVSS 7.5
CVE-2020-11080 [LOW] CWE-707 Denial of service in nghttp2
Denial of service in nghttp2
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/
Red Hat
nghttp2: overly large SETTINGS frames can lead to DoS
vendor_redhat·2020-06-02·CVSS 3.7
CVE-2020-11080 [LOW] CWE-770 nghttp2: overly large SETTINGS frames can lead to DoS
nghttp2: overly large SETTINGS frames can lead to DoS
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.
A resource consumption vulnerability was found in nghttp2. This flaw allows an attacker to repeatedly construct an overly large HTTP/2 SETTINGS frame with a l
Debian
CVE-2020-11080: nghttp2 - In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload...
vendor_debian·2020·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080: nghttp2 - In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload...
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.
Scope: local
bookworm: resolved (fixed in 1.41.0-1)
bullseye: resolved (fixed in 1.41.0-1)
forky: resolved (fixed in 1.41.0-1)
sid: resolved (fixed in 1.41.0-1)
trixie: resolved (fixed in 1.41.0-1)
OSV
CVE-2020-11080: In nghttp2 before version 1
osv·2020-06-03·CVSS 7.5
CVE-2020-11080 [HIGH] CVE-2020-11080: In nghttp2 before version 1
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11080 nodejs:12/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
bugzilla·2020-06-16·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080 nodejs:12/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
CVE-2020-11080 nodejs:12/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-11080 nodejs:11/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
bugzilla·2020-06-16·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080 nodejs:11/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
CVE-2020-11080 nodejs:11/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-11080 nodejs:10/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
bugzilla·2020-06-16·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080 nodejs:10/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
CVE-2020-11080 nodejs:10/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-11080 nodejs:13/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
bugzilla·2020-06-16·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080 nodejs:13/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
CVE-2020-11080 nodejs:13/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-11080 nodejs:14/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
bugzilla·2020-06-16·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080 nodejs:14/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
CVE-2020-11080 nodejs:14/nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-11080 nghttp2: overly large SETTIGNS frames can lead to DoS [epel-8]
bugzilla·2020-06-08·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080 nghttp2: overly large SETTIGNS frames can lead to DoS [epel-8]
CVE-2020-11080 nghttp2: overly large SETTIGNS frames can lead to DoS [epel-8]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-8.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedp
Bugzilla
CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS [epel-7]
bugzilla·2020-06-08·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS [epel-7]
CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedp
Bugzilla
CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
bugzilla·2020-06-08·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS
bugzilla·2020-06-08·CVSS 3.7
CVE-2020-11080 [LOW] CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS
CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS
In nghttp2 before version 1.41.0, if an overly large HTTP/2 SETTINGS frame with a length of 14,400 bytes is repeatedly constructed it can cause the CPU to spike to 100% and cause a DoS.
Discussion:
External References:
https://github.com/nghttp2/nghttp2/security/advisories/GHSA-q5wr-xfw9-q7xr
---
Created nghttp2 tracking bugs for this issue:
Affects: epel-7 [bug 1844931]
Affects: epel-8 [bug 1844932]
Affects: fedora-all [bug 1844930]
---
Acknowledgments:
Name: the Envoy security team
---
(In reply to Mark Cooper from comment #2)
> Created nghttp2 tracking bugs for this issue:
>
> Affects: epel-7 [bug 1844931]
> Affects: epel-8 [bug 1844932]
nghttp2 is not in epel-8. Please consider creating a rhel-8 tracking
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.htmlhttps://github.com/nghttp2/nghttp2/commit/336a98feb0d56b9ac54e12736b18785c27f75090https://github.com/nghttp2/nghttp2/commit/f8da73bd042f810f34d19f9eae02b46d870af394https://github.com/nghttp2/nghttp2/security/advisories/GHSA-q5wr-xfw9-q7xrhttps://lists.debian.org/debian-lts-announce/2021/10/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AAC2AA36OTRHKSVM5OV7TTVB3CZIGEFL/https://www.debian.org/security/2020/dsa-4696https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.htmlhttps://github.com/nghttp2/nghttp2/commit/336a98feb0d56b9ac54e12736b18785c27f75090https://github.com/nghttp2/nghttp2/commit/f8da73bd042f810f34d19f9eae02b46d870af394https://github.com/nghttp2/nghttp2/security/advisories/GHSA-q5wr-xfw9-q7xrhttps://lists.debian.org/debian-lts-announce/2021/10/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AAC2AA36OTRHKSVM5OV7TTVB3CZIGEFL/https://www.debian.org/security/2020/dsa-4696https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-06-03
Published