> USN-8233-1: nghttp2 vulnerability
[DATE: 05/05/2026 17:07]
[LANGUAGE: EN]
Andrew MacPherson discovered that nghttp2 did not properly validate
internal state when the session termination API was called. A remote
attacker could possibly use this issue to cause nghttp2 to crash, resulting
in a denial of service.