nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4581-1 nghttp2 security update
Debian DSA Debian DSA DSA-6266-1 nghttp2 security update
Ubuntu USN Ubuntu USN USN-8233-1 nghttp2 vulnerability
Ubuntu USN Ubuntu USN USN-8233-2 nghttp2 vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://www.openwall.com/lists/oss-security/2026/03/20/3 cve-icon
https://access.redhat.com/errata/RHSA-2026:10065 cve-icon
https://access.redhat.com/errata/RHSA-2026:11768 cve-icon
https://access.redhat.com/errata/RHSA-2026:13812 cve-icon
https://access.redhat.com/errata/RHSA-2026:14773 cve-icon
https://access.redhat.com/errata/RHSA-2026:14937 cve-icon
https://access.redhat.com/errata/RHSA-2026:15087 cve-icon
https://access.redhat.com/errata/RHSA-2026:16008 cve-icon
https://access.redhat.com/errata/RHSA-2026:16009 cve-icon
https://access.redhat.com/errata/RHSA-2026:16030 cve-icon
https://access.redhat.com/errata/RHSA-2026:16174 cve-icon
https://access.redhat.com/errata/RHSA-2026:17596 cve-icon
https://access.redhat.com/errata/RHSA-2026:19724 cve-icon
https://access.redhat.com/errata/RHSA-2026:19725 cve-icon
https://access.redhat.com/errata/RHSA-2026:20040 cve-icon
https://access.redhat.com/errata/RHSA-2026:20087 cve-icon
https://access.redhat.com/errata/RHSA-2026:21656 cve-icon
https://access.redhat.com/errata/RHSA-2026:21690 cve-icon
https://access.redhat.com/errata/RHSA-2026:21695 cve-icon
https://access.redhat.com/errata/RHSA-2026:25096 cve-icon
https://access.redhat.com/errata/RHSA-2026:27200 cve-icon
https://access.redhat.com/errata/RHSA-2026:27201 cve-icon
https://access.redhat.com/errata/RHSA-2026:6190 cve-icon
https://access.redhat.com/errata/RHSA-2026:7080 cve-icon
https://access.redhat.com/errata/RHSA-2026:7123 cve-icon
https://access.redhat.com/errata/RHSA-2026:7302 cve-icon
https://access.redhat.com/errata/RHSA-2026:7310 cve-icon
https://access.redhat.com/errata/RHSA-2026:7350 cve-icon
https://access.redhat.com/errata/RHSA-2026:7666 cve-icon
https://access.redhat.com/errata/RHSA-2026:7667 cve-icon
https://access.redhat.com/errata/RHSA-2026:7668 cve-icon
https://access.redhat.com/errata/RHSA-2026:7670 cve-icon
https://access.redhat.com/errata/RHSA-2026:7675 cve-icon
https://access.redhat.com/errata/RHSA-2026:7896 cve-icon
https://access.redhat.com/errata/RHSA-2026:7983 cve-icon
https://access.redhat.com/errata/RHSA-2026:8339 cve-icon
https://access.redhat.com/errata/RHSA-2026:8538 cve-icon
https://access.redhat.com/errata/RHSA-2026:8539 cve-icon
https://access.redhat.com/errata/RHSA-2026:8540 cve-icon
https://access.redhat.com/errata/RHSA-2026:8541 cve-icon
https://access.redhat.com/errata/RHSA-2026:8545 cve-icon
https://access.redhat.com/errata/RHSA-2026:8546 cve-icon
https://access.redhat.com/errata/RHSA-2026:8547 cve-icon
https://access.redhat.com/errata/RHSA-2026:8548 cve-icon
https://access.redhat.com/errata/RHSA-2026:8868 cve-icon
https://access.redhat.com/errata/RHSA-2026:9711 cve-icon
https://access.redhat.com/errata/RHSA-2026:9832 cve-icon
https://access.redhat.com/errata/RHSA-2026:9874 cve-icon
https://access.redhat.com/security/cve/CVE-2026-27135 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2448754 cve-icon
https://cert-portal.siemens.com/productcert/html/ssa-019113.html cve-icon
https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1 cve-icon cve-icon cve-icon
https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6 cve-icon cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2026/05/msg00025.html cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-27135 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-27135 cve-icon
History

Wed, 13 May 2026 22:30:00 +0000

Type Values Removed Values Added
References

Mon, 23 Mar 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:*

Fri, 20 Mar 2026 22:30:00 +0000

Type Values Removed Values Added
References

Fri, 20 Mar 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 19 Mar 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Nghttp2
Nghttp2 nghttp2
Vendors & Products Nghttp2
Nghttp2 nghttp2

Wed, 18 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Description nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.
Title nghttp2 Denial of service: Assertion failure due to the missing state validation
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-15T01:14:36.116Z

Reserved: 2026-02-17T18:42:27.044Z

Link: CVE-2026-27135

cve-icon Vulnrichment

Updated: 2026-05-13T21:31:25.337Z

cve-icon NVD

Status : Modified

Published: 2026-03-18T18:16:26.723

Modified: 2026-07-15T02:19:03.367

Link: CVE-2026-27135

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-18T17:59:02Z

Links: CVE-2026-27135 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-03-24T10:58:04Z

Weaknesses