CVE-2018-16844: High severity Apple Xcode vulnerability
Published Oct 31, 2018
·Updated
IDE Xcode Server. Multiple issues were addressed by updating nginx to version 1.21.0.
Other sources
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage.
— Red Hat
Credit
CVE-2016-0742, CVE-2016-0746, CVE-2016-0747, CVE-2017-7529, CVE-2018-16843, CVE-2018-16844, CVE-2018-16845, CVE-2019-20372
Affected Software
12 affected componentsFixes available
redhat/nginx<1.15.6
1.15.6
redhat/nginx<1.14.1
1.14.1
Apple Xcode<13
13
F5 Nginx>=1.9.5<1.14.1
F5 Nginx>=1.15.0<1.15.6
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Apple Xcode<13.0
debian/nginx
1.18.0-6.1+deb11u31.18.0-6.1+deb11u51.22.1-9+deb12u31.22.1-9+deb12u41.26.3-3+deb13u11.26.3-3+deb13u21.28.2-2
Remediation
Patch Available
Event History
Nov 7, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:54 PM
Description
Feb 22, 2026
Data Sourced
via Ubuntu·05:45 PM
RemedyDescriptionSeverityAffected Software
Feb 23, 2026
Data Sourced
via Debian·05:46 PM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2018-16844?
CVE-2018-16844 is a vulnerability in nginx before versions 1.15.6 and 1.14.1 that allows for excessive CPU usage due to a flaw in the implementation of HTTP/2.
2
Who is affected by CVE-2018-16844?
Users of the affected versions of nginx (1.15.6 and 1.14.1) and Xcode are affected by CVE-2018-16844.
3
How do I fix CVE-2018-16844?
To fix CVE-2018-16844, update nginx to version 1.21.0 or later.
4
Where can I find more information about CVE-2018-16844?
You can find more information about CVE-2018-16844 in the references provided.
5
What is the severity of CVE-2018-16844?
CVE-2018-16844 has a severity rating of 7.5 (high).