Known Vulnerabilities for Http2 by Golang

Listed below are 3 of the newest known vulnerabilities associated with "Http2" by "Golang".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-50560 json Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and... Not Provided 2026-06-12 2026-06-13
CVE-2026-50052 json In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch... Not Provided 2026-06-03 2026-06-03
CVE-2026-48862 json Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 serv... Not Provided 2026-06-02 2026-06-02
CVE-2026-48043 json Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versi... Not Provided 2026-06-12 2026-06-12
CVE-2026-47139 json vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from... Not Provided 2026-06-12 2026-06-12
CVE-2026-42788 json Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion... Not Provided 2026-05-01 2026-05-04
CVE-2026-31935 json Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frame... Not Provided 2026-04-02 2026-04-02
CVE-2026-21714 json A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that c... Not Provided 2026-03-30 2026-03-31
CVE-2026-10725 json Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no he... Not Provided 2026-06-06 2026-06-09
CVE-2023-39325 json A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource cons... 7.5 - HIGH 2023-10-11 2024-03-10
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report