VDB

GCVE-VVD-MAGEIA-2024-135

GCVE-VVD-MAGEIA-2024-135
Advisory Published
Vulnetix · Advisory published April 29, 2024
nghttp2 library keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. This update fixes the issue. This is the latest release, which will bring some more fixes and improvements.

Affected Products

VendorProductVersionsPlatforms
Mageiadrakconf0 (affected), 13.29-1.1.mga9 (unaffected)
Mageianghttp20 (affected), 1.61.0-1.mga9 (unaffected), 0 (affected), 1.61.0-1.mga9 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›