Known Vulnerabilities for Http2 by Golang
Listed below are 3 of the newest known vulnerabilities associated with "Http2" by "Golang".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64785 json | SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach ... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-59246 json | Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory on t... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-55629 json | Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-50560 json | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and... | Not Provided | 2026-06-12 | 2026-06-13 |
| CVE-2026-50052 json | In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch... | Not Provided | 2026-06-03 | 2026-07-01 |
| CVE-2026-48862 json | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 serv... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-48043 json | Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versi... | Not Provided | 2026-06-12 | 2026-07-30 |
| CVE-2026-47139 json | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-42788 json | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion... | Not Provided | 2026-05-01 | 2026-05-04 |
| CVE-2026-28898 json | swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them i... | Not Provided | 2026-06-25 | 2026-06-25 |