Security readout for executives and security teams
CVE-2018-1000168 is a denial-of-service flaw in nghttp2. A malformed ALTSVC HTTP/2 frame can crash affected software with a segmentation fault, causing availability loss. The provided sources identify affected nghttp2 versions from 1.10.0 through 1.31.0, fixed in 1.31.1 or later. Exposure is most likely in systems that use vulnerable nghttp2 directly or through vendor-packaged software, especially HTTP/2-enabled client or server components. Red Hat, Debian LTS, Node.js, and nghttp2 references indicate downstream packaging relevance. Prioritize patching internet-facing or availability-sensitive systems using vulnerable nghttp2. The issue is high severity because it can be triggered remotely without authentication, but the impact described is service disruption rather than data theft or code execution. Mitigation focus: Upgrade nghttp2 to version 1.31.1 or later where directly managed.; Apply relevant vendor updates for Red Hat, Debian, Node.js, or other bundled nghttp2 consumers.; Inventory HTTP/2-enabled services and applications that depend on nghttp2..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-476: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2018-1000168 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.5HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- RHSA-2019:0367CVE reference · vendor-advisory, x_refsource_REDHAT
- https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/CVE reference · x_refsource_CONFIRM
- https://nghttp2.org/blog/2018/04/12/nghttp2-v1-31-1/CVE reference · x_refsource_CONFIRM
- RHSA-2019:0366CVE reference · vendor-advisory, x_refsource_REDHAT
- [debian-lts-announce] 20211017 [SECURITY] [DLA 2786-1] nghttp2 security updateCVE reference · mailing-list, x_refsource_MLIST
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
NULL Pointer Dereference
NULL Pointer Dereference represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
