CVE-2026-27135Patch(nghttp2 / nghttp2)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nghttp2 nghttp2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nghttp2

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 7d ago at 2 mentions (2026-03-18); latest day: 1
  • 10 total mentions across 8 days

Affected systems

Vendors
Products
nghttp2

Deep dive

Activity timeline10 mentions / 8d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-21: 1Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Mentions · 2026-04-02: 1Mentions · 2026-04-11: 1Mentions · 2026-04-14: 1Mentions · 2026-07-17: 1PoC Mentioned / Linked · 2026-03-24: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-23: 2Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-07-17: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-21: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-11: 1Technical Details · 2026-07-17: 103-1803-2103-2303-2404-0204-1104-1407-17
Signal classification3 categories
Patch
660.0%
Disclosure
330.0%
General
110.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-182
General1Patch1
2026-03-211
Disclosure1
2026-03-232
Patch2
2026-03-241
Disclosure1
2026-04-021
Patch1
2026-04-111
Patch1
2026-04-141
Disclosure1
2026-07-171
Patch1
Full discourse10 posts
  • AndrewMohawk⁽ⁿᵘˡˡ⁾@AndrewMohawk
    Disclosure

    Another CVE from working with codex last month: CVE-2026-27135 https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6

    Post summary

    The brief post points out a newly identified CVE and links to its GitHub advisory, but it offers no additional insights into exploitation, patch status, or technical details.

    00193783
    5.3K followersView on X
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.52 is now available: • NGINX→ 1.29.7 (proxy_http_version update, listed CVEs • Node.js 22→ 22.22.2, Node.js 20→ 20.20.2, listed CVEs • libxml2→ 2.15.2, nghttp2→ 1.68.1 (CVE-2026-27135), Tomcat→ 10.1.53 • PHP memcached ext→ 3.4.0 https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ https://t.co/3AaQQkRfVu

    Post summary

    The announcement details a new EasyApache 4 release that patches multiple components, including a CVE-2026-27135 fix, and provides links to the official change log.

    10150398
    28.8K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-27135: nghttp2: DoS through assertion failure due to missing state validation https://www.openwall.com/lists/oss-security/2026/03/20/3

    Post summary

    The notice announces CVE-2026-27135, a denial‑of‑service flaw in nghttp2 caused by an assertion failure due to missing state validation, and links to a mailing‑list discussion. No evidence of exploitation, PoC, or patch is provided.

    00021373
    4.4K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nghttp2 モジュール更新情報 1.68.1-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nghttp2 1.68.1-1 この更新には脆弱性(CVE-2026-27135)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # dnf upgrade アップデート後、以下のコマンドで再起動してください。 ... https://kusanagi.tokyo/releases/23766/

    Post summary

    The post announces a module update for kusanagi-nghttp2 that addresses CVE-2026-27135, providing upgrade instructions and a link to the release page.

    0101068
    198 followersView on X
  • VulniPulse@vulnipulse
    Patch

    ⚠️ NetApp Active IQ Unified Manager for VMware vSphere alert: CVE-2026-27135 (CVSS 7.5) Attackers could disrupt service or cause a denial of service. No workaround is available; follow the vendor advisory for updates. https://vulnipulse.com/advisories/netapp-ntap-20260717-0011 #NetApp #CyberSecurity #CVE

    Post summary

    CVE-2026-27135 poses a denial‑of‑service risk (CVSS 7.5) for NetApp Active IQ Unified Manager on VMware vSphere; no workaround exists and users are advised to follow the vendor advisory for updates.

    0000038
    6 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-27135 impacts libnghttp2 in 20 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/467 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The tweet announces a newly detected high‑severity CVE (CVE‑2026‑27135) affecting AWS Lambda base images, but offers no details on exploitation, mitigation, or technical specifics.

    0000022
    34 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Breaking news. CVE-2026-27135 (nghttp2 assertion DoS) is fixed, but the process to detect, patch, and mitigate is what keeps you safe. Read more: 👉 https://tinyurl.com/mhap9fe #SUSE https://t.co/pVPnq9aN0E

    Post summary

    The tweet announces that CVE‑2026‑27135, an assertion‑based DoS in nghttp2, has been fixed and emphasizes the need for timely detection and patching.

    0000076
    1.5K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nghttp2 Module Update 1.68.1-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nghttp2 1.68.1-1 This update includes support for vulnerability(CVE-2026-27135). The module update can be applied with the... https://kusanagi.tokyo/en/releases/23767/

    Post summary

    A module update for Kusanagi’s nghttp2 (v1.68.1-1) has been released to address CVE-2026-27135, providing a patch for the vulnerability.

    0000032
    198 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27135 nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user… https://www.cve.org/CVERecord?id=CVE-2026-27135

    Post summary

    The text briefly references CVE‑2026‑27135, mentioning a behavior of the nghttp2 library without providing any proof of concept, exploit details, active exploitation reports, or mitigation information.

    0000074
    56.8K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-27135: Malformed HTTP/2 frames can crash apps using nghttp2 ≤1.68.0 (remote denial of service, no login). Update to 1.68.1 now! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-27135 #nghttp2 #infosec #DevOps

    Post summary

    The advisory warns that malformed HTTP/2 frames can crash applications using nghttp2 ≤ 1.68.0, causing remote denial of service, and recommends updating to 1.68.1.

    0000047
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnghttp2nghttp2---

Explore more