The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
{
"availability": "No subscription required",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libnghttp2-14",
"binary_version": "1.40.0-1ubuntu0.2"
},
{
"binary_name": "libnghttp2-dev",
"binary_version": "1.40.0-1ubuntu0.2"
},
{
"binary_name": "nghttp2",
"binary_version": "1.40.0-1ubuntu0.2"
},
{
"binary_name": "nghttp2-client",
"binary_version": "1.40.0-1ubuntu0.2"
},
{
"binary_name": "nghttp2-proxy",
"binary_version": "1.40.0-1ubuntu0.2"
},
{
"binary_name": "nghttp2-server",
"binary_version": "1.40.0-1ubuntu0.2"
}
]
}{
"availability": "No subscription required",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libtomcat9-embed-java",
"binary_version": "9.0.31-1ubuntu0.9"
},
{
"binary_name": "libtomcat9-java",
"binary_version": "9.0.31-1ubuntu0.9"
},
{
"binary_name": "tomcat9",
"binary_version": "9.0.31-1ubuntu0.9"
},
{
"binary_name": "tomcat9-admin",
"binary_version": "9.0.31-1ubuntu0.9"
},
{
"binary_name": "tomcat9-common",
"binary_version": "9.0.31-1ubuntu0.9"
},
{
"binary_name": "tomcat9-docs",
"binary_version": "9.0.31-1ubuntu0.9"
},
{
"binary_name": "tomcat9-examples",
"binary_version": "9.0.31-1ubuntu0.9"
},
{
"binary_name": "tomcat9-user",
"binary_version": "9.0.31-1ubuntu0.9"
}
]
}{
"availability": "No subscription required",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "aspnetcore-runtime-6.0",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "aspnetcore-targeting-pack-6.0",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-apphost-pack-6.0",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-host",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-hostfxr-6.0",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-runtime-6.0",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-sdk-6.0",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-sdk-6.0-source-built-artifacts",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-targeting-pack-6.0",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-templates-6.0",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet6",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
},
{
"binary_name": "netstandard-targeting-pack-2.1",
"binary_version": "6.0.123-0ubuntu1~22.04.1"
}
]
}{
"availability": "No subscription required",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "aspnetcore-runtime-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "aspnetcore-targeting-pack-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-apphost-pack-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-host-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-hostfxr-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-runtime-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-sdk-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-sdk-7.0-source-built-artifacts",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-targeting-pack-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet-templates-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "dotnet7",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
},
{
"binary_name": "netstandard-targeting-pack-2.1-7.0",
"binary_version": "7.0.112-0ubuntu1~22.04.1"
}
]
}{
"availability": "No subscription required",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libnghttp2-14",
"binary_version": "1.43.0-1ubuntu0.1"
},
{
"binary_name": "libnghttp2-dev",
"binary_version": "1.43.0-1ubuntu0.1"
},
{
"binary_name": "nghttp2",
"binary_version": "1.43.0-1ubuntu0.1"
},
{
"binary_name": "nghttp2-client",
"binary_version": "1.43.0-1ubuntu0.1"
},
{
"binary_name": "nghttp2-proxy",
"binary_version": "1.43.0-1ubuntu0.1"
},
{
"binary_name": "nghttp2-server",
"binary_version": "1.43.0-1ubuntu0.1"
}
]
}{
"availability": "No subscription required",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libtomcat9-embed-java",
"binary_version": "9.0.58-1ubuntu0.2"
},
{
"binary_name": "libtomcat9-java",
"binary_version": "9.0.58-1ubuntu0.2"
},
{
"binary_name": "tomcat9",
"binary_version": "9.0.58-1ubuntu0.2"
},
{
"binary_name": "tomcat9-admin",
"binary_version": "9.0.58-1ubuntu0.2"
},
{
"binary_name": "tomcat9-common",
"binary_version": "9.0.58-1ubuntu0.2"
},
{
"binary_name": "tomcat9-docs",
"binary_version": "9.0.58-1ubuntu0.2"
},
{
"binary_name": "tomcat9-examples",
"binary_version": "9.0.58-1ubuntu0.2"
},
{
"binary_name": "tomcat9-user",
"binary_version": "9.0.58-1ubuntu0.2"
}
]
}{
"availability": "No subscription required",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "aspnetcore-runtime-8.0",
"binary_version": "8.0.0-0ubuntu1"
},
{
"binary_name": "aspnetcore-targeting-pack-8.0",
"binary_version": "8.0.0-0ubuntu1"
},
{
"binary_name": "dotnet-apphost-pack-8.0",
"binary_version": "8.0.0-0ubuntu1"
},
{
"binary_name": "dotnet-host-8.0",
"binary_version": "8.0.0-0ubuntu1"
},
{
"binary_name": "dotnet-hostfxr-8.0",
"binary_version": "8.0.0-0ubuntu1"
},
{
"binary_name": "dotnet-runtime-8.0",
"binary_version": "8.0.0-0ubuntu1"
},
{
"binary_name": "dotnet-sdk-8.0",
"binary_version": "8.0.100-0ubuntu1"
},
{
"binary_name": "dotnet-sdk-8.0-source-built-artifacts",
"binary_version": "8.0.100-0ubuntu1"
},
{
"binary_name": "dotnet-targeting-pack-8.0",
"binary_version": "8.0.0-0ubuntu1"
},
{
"binary_name": "dotnet-templates-8.0",
"binary_version": "8.0.100-0ubuntu1"
},
{
"binary_name": "dotnet8",
"binary_version": "8.0.100-8.0.0-0ubuntu1"
},
{
"binary_name": "netstandard-targeting-pack-2.1-8.0",
"binary_version": "8.0.100-0ubuntu1"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libnghttp2-14",
"binary_version": "1.7.1-1ubuntu0.1~esm2"
},
{
"binary_name": "libnghttp2-dev",
"binary_version": "1.7.1-1ubuntu0.1~esm2"
},
{
"binary_name": "nghttp2",
"binary_version": "1.7.1-1ubuntu0.1~esm2"
},
{
"binary_name": "nghttp2-client",
"binary_version": "1.7.1-1ubuntu0.1~esm2"
},
{
"binary_name": "nghttp2-proxy",
"binary_version": "1.7.1-1ubuntu0.1~esm2"
},
{
"binary_name": "nghttp2-server",
"binary_version": "1.7.1-1ubuntu0.1~esm2"
}
]
}{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "haproxy",
"binary_version": "1.8.8-1ubuntu0.13+esm3"
},
{
"binary_name": "vim-haproxy",
"binary_version": "1.8.8-1ubuntu0.13+esm3"
}
]
}{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libnghttp2-14",
"binary_version": "1.30.0-1ubuntu1+esm2"
},
{
"binary_name": "libnghttp2-dev",
"binary_version": "1.30.0-1ubuntu1+esm2"
},
{
"binary_name": "nghttp2",
"binary_version": "1.30.0-1ubuntu1+esm2"
},
{
"binary_name": "nghttp2-client",
"binary_version": "1.30.0-1ubuntu1+esm2"
},
{
"binary_name": "nghttp2-proxy",
"binary_version": "1.30.0-1ubuntu1+esm2"
},
{
"binary_name": "nghttp2-server",
"binary_version": "1.30.0-1ubuntu1+esm2"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "h2o",
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2"
},
{
"binary_name": "libh2o-dev",
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2"
},
{
"binary_name": "libh2o-dev-common",
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2"
},
{
"binary_name": "libh2o-evloop-dev",
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2"
},
{
"binary_name": "libh2o-evloop0.13",
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2"
},
{
"binary_name": "libh2o0.13",
"binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "nodejs",
"binary_version": "8.10.0~dfsg-2ubuntu0.4+esm6"
},
{
"binary_name": "nodejs-dev",
"binary_version": "8.10.0~dfsg-2ubuntu0.4+esm6"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libtomcat8-embed-java",
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4"
},
{
"binary_name": "libtomcat8-java",
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4"
},
{
"binary_name": "tomcat8",
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4"
},
{
"binary_name": "tomcat8-admin",
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4"
},
{
"binary_name": "tomcat8-common",
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4"
},
{
"binary_name": "tomcat8-docs",
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4"
},
{
"binary_name": "tomcat8-examples",
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4"
},
{
"binary_name": "tomcat8-user",
"binary_version": "8.5.39-1ubuntu1~18.04.3+esm4"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libtomcat9-embed-java",
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5"
},
{
"binary_name": "libtomcat9-java",
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5"
},
{
"binary_name": "tomcat9",
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5"
},
{
"binary_name": "tomcat9-admin",
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5"
},
{
"binary_name": "tomcat9-common",
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5"
},
{
"binary_name": "tomcat9-docs",
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5"
},
{
"binary_name": "tomcat9-examples",
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5"
},
{
"binary_name": "tomcat9-user",
"binary_version": "9.0.16-3ubuntu0.18.04.2+esm5"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libnode-dev",
"binary_version": "10.19.0~dfsg-3ubuntu1.6+esm2"
},
{
"binary_name": "libnode64",
"binary_version": "10.19.0~dfsg-3ubuntu1.6+esm2"
},
{
"binary_name": "nodejs",
"binary_version": "10.19.0~dfsg-3ubuntu1.6+esm2"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "trafficserver",
"binary_version": "8.0.5+ds-3ubuntu0.1~esm1"
},
{
"binary_name": "trafficserver-dev",
"binary_version": "8.0.5+ds-3ubuntu0.1~esm1"
},
{
"binary_name": "trafficserver-experimental-plugins",
"binary_version": "8.0.5+ds-3ubuntu0.1~esm1"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "libnode-dev",
"binary_version": "12.22.9~dfsg-1ubuntu3.6+esm2"
},
{
"binary_name": "libnode72",
"binary_version": "12.22.9~dfsg-1ubuntu3.6+esm2"
},
{
"binary_name": "nodejs",
"binary_version": "12.22.9~dfsg-1ubuntu3.6+esm2"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"priority_reason": "Listed in CISA Known Exploited Vulnerabilities Catalog",
"binaries": [
{
"binary_name": "trafficserver",
"binary_version": "9.1.1+ds-2ubuntu0.1~esm1"
},
{
"binary_name": "trafficserver-dev",
"binary_version": "9.1.1+ds-2ubuntu0.1~esm1"
},
{
"binary_name": "trafficserver-experimental-plugins",
"binary_version": "9.1.1+ds-2ubuntu0.1~esm1"
}
]
}