CVE-2016-1544: Fedoraproject Fedora

Low severity, CVSS 3.3. EPSS: 0.9% chance of exploitation in the next 30 days.

nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).

Affected products

  • Fedoraproject Fedora: version 22 only; version 23 only
  • NGHTTP2 NGHTTP2: before 1.7.1 (fixed in 1.7.1)

Published 2020-02-06. Last modified 2026-06-17.