Two security issue have been discovered in nghttp2: server, proxy and client implementing HTTP/2.
CVE-2018-1000168
An Improper Input Validation CWE-20 vulnerability found in ALTSVC frame handling
that can result in segmentation fault leading to denial of service. This attack
appears to be exploitable via network client.
CVE-2020-11080
The overly large HTTP/2 SETTINGS frame payload causes denial of service.
The proof of concept attack involves a malicious client constructing a SETTINGS
frame with a length of 14,400 bytes (2400 individual settings entries) over and over again.
The attack causes the CPU to spike at 100%.
1.18.1-1+deb9u2