« List of all CVEs

CVE-2024-39936

Published: 7/4/2024 Last updated: 3/19/2025 Reserved: 7/4/2024

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 8.6 High CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:C/UI:N

Opam packages affected (2)

conf-qt oqamldebug

Products affected (1)

Product Vendor Version
n/a n/a 2.4.1

References (2)