Description
All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0595 | All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function. |
Github GHSA |
GHSA-2275-rpf5-xv8h | is-http2 vulnerable to Improper Input Validation |
References
History
Wed, 26 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-03-26T20:22:01.409Z
Reserved: 2022-02-24T11:58:26.981Z
Link: CVE-2022-25906
Updated: 2024-08-03T04:49:44.472Z
Status : Modified
Published: 2023-02-01T05:15:11.960
Modified: 2025-03-26T21:15:17.910
Link: CVE-2022-25906
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA