CVSS v3
7.5
HIGH
EPSS Score
23.3%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.
Active exploitation of CVE-2019-10081 has not been confirmed. The EPSS score is 23.3%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2019-10081 has a CVSS v3 base score of 7.5 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).