VDB
RHSA-2026%3A8868
RHSA-2026%3A8868
PUBLISHED
CVSS 7.5 HIGH
An update for nghttp2 is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| libnghttp2 | ||
| Red Hat Enterprise Linux BaseOS EUS (v. 10.0) | ||
| Red Hat Enterprise Linux AppStream EUS (v. 10.0) | ||
| nghttp2 | ||
| Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) |
Timeline
- Apr 20, 2026 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Security Advisory
- May 1, 2026 Security Advisory
- Jun 25, 2026 CVE Updated