CVE-2016-7153
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content lengt
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
MEDIUM · CVSS 5.3
EPSS 0.01253
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules5
YARA rules0