Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
Vulnerability Description
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-27316
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Bartek Nowotarski (https://nowotarski.info/)
References
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →