VYPR
Critical severity10.0NVD Advisory· Published Jan 12, 2016· Updated May 6, 2026

CVE-2015-8659

CVE-2015-8659

Description

The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.