← Back

CVE-2020-11080

nvd nist
Published: Jun 3, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.

Affected (23)

Products: Nghttp2: Nghttp2 · Debian: Debian Linux · Opensuse: Leap · +3 more
Show all products
1 product
Nghttp2
1 product
Debian Linux
1 product
Leap
1 product
Fedora
5 products
Banking Extensibility Workbench
Blockchain Platform
Enterprise Communications Broker
Graalvm
Mysql
1 product
Node.js
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.41.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 31
Version 33
Configuration E
12 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 14.3.0
Version 14.4.0
Before 21.1.2
Oracle
Version 3.1.0
Version 3.2.0
Oracle
Version 19.3.2
Version 20.1.0
Oracle
From 7.3.0 to 7.3.30
From 7.4.0 to 7.4.29
From 7.5.0 to 7.5.19
From 7.6.0 to 7.6.15
From 8.0.0 to 8.0.21
Configuration F
5 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 10.0.0 to 10.12.0
From 12.0.0 to 12.12.0
From 14.0.0 to 14.4.0
From 10.13.0 to 10.21.0
From 12.13.0 to 12.18.0

References (28)

Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Not ApplicableThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.