https://seclists.org/oss-sec/2026/q1/357: nghttp2 Denial of service: Assertion failudue to the missing state validation
Published Mar 20, 2026
·Updated
Affected Software
1 affected component
nghttp2 nghttp2<1.68.1
Frequently Asked Questions
1
What is the severity of GHSA-6933-cjhr-5qg6?
The severity of GHSA-6933-cjhr-5qg6 is considered high due to its potential to cause denial of service.
2
How do I fix GHSA-6933-cjhr-5qg6?
To fix GHSA-6933-cjhr-5qg6, you should upgrade to the patched version of nghttp2 as specified in the advisory.
3
What causes the vulnerability GHSA-6933-cjhr-5qg6?
The vulnerability GHSA-6933-cjhr-5qg6 is caused by an assertion failure due to missing state validation when certain session termination functions are invoked.
4
What are the consequences of exploiting GHSA-6933-cjhr-5qg6?
Exploiting GHSA-6933-cjhr-5qg6 can lead to a denial of service, effectively stopping the nghttp2 library from processing incoming data.
5
Which versions of nghttp2 are affected by GHSA-6933-cjhr-5qg6?
GHSA-6933-cjhr-5qg6 affects certain prior versions of the nghttp2 library before the release of the patched version.