Back to Database
Status published
High
CVE-2024-23837
LibHTP unbounded folded header handling leads to denial service
Vulnerability Description
LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-23837
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/OISF/libhtp/security/advisories/GHSA-f9wf-rrjj-qx8m
- https://github.com/OISF/libhtp/commit/20ac301d801cdf01b3f021cca08a22a87f477c4a
- https://redmine.openinfosecfoundation.org/issues/6444
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GOCOBFUTIFHOP2PZOH4ENRFXRBHIRKK4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXJIT7R53ZXROO3I256RFUWTIW4ECK6P/
More from OISF
View All →CVE-2025-64344
Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBuffer
High
7.5
CVE-2025-64335
Suricata is vulnerable to a null deref when used with base64_data
High
7.5
CVE-2025-64334
Suricata is vulnerable to unbounded memory growth for decompression
High
7.5
CVE-2025-64333
Suricata is vulnerable to a stack overflow from big content-type
High
7.5
CVE-2025-64332
Suricata is vulnerable to a stack overflow on larger compressed data
High
7.5
Affected Vendor
OISF
View all reports →Affected Software
libhtp
Vulnerable Versions:
< 0.5.46
Timeline
Official Publish:
February 26th, 2024
Last Modified:
November 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H