Skip to content

HTTP/2 Server Denial of Service Risks

High
Lukasa published GHSA-jchv-x857-q8fq Aug 13, 2019 · 1 comment

Package

swift swift-nio-http2 (Swift)

Affected versions

>=1.0.0,<1.5.0

Patched versions

1.5.0

Description

This is an umbrella advisory for a family of associated security releases. There are specific sub-advisories for each CVE.

Impact

Denial of service attack on HTTP/2 servers.

Patches

Available in 1.5.0.

Workarounds

There is no meaningful workaround without applying these patches.

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs