> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Debian DSA-6266-1 nghttp2 Critical DoS Exploit CVE-2026-27135

[SOURCE] LinuxSecurity - Debian [DATE: 14/05/2026 08:47] [LANGUAGE: EN]
It was discovered that nghttp2, an implementation of the HTTP/2 protocol, could be crashed via an assertion failure. A remote attacker could exploit this to cause a DoS attack by sending a malformed frame immediately after triggering the termination path. For the oldstable distribution (bookworm), this problem has been fixed
[messages.read_original_source] →