golang.org/x/net/http2 vulnerabilities
CVEs whose affected-version data names the golang.org/x/net/http2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2023-45288Medium· 5.3PoCnet/http, x/net/http2: close connections when receiving too many headers
net/http, x/net/http2: close connections when receiving too many headers
▾ Twilightnet · net/httpEPSS 92%via OSV
CVE-2022-27664High· 7.5golang.org/x/net/http2 Denial of Service vulnerability
golang.org/x/net/http2 Denial of Service vulnerability
▾ Twilightx · golang.org/x/netEPSS 3.3%via OSV