Back to Database
Status published
High
CVE-2024-29904
CodeIgniter4 Language class DoS Vulnerability
Vulnerability Description
CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7 or later.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-29904
Credits & Attribution
No credits recorded in the NVD database.
References
More from codeigniter4
View All →CVE-2025-54418
CodeIgniter4's ImageMagick Handler has Command Injection Vulnerability
Critical
9.8
CVE-2025-24013
CodeIgniter validation of header name and value
Medium
5.3
CVE-2023-48708
Insertion of Sensitive Information into Log in codeigniter4/shield
Medium
5
CVE-2023-48707
Cleartext Storage of Sensitive Information in codeigniter4/shield
Medium
5
CVE-2023-46240
CodeIgniter4 vulnerable to information disclosure when detailed error report is displayed in production environment
High
7.5
Affected Vendor
codeigniter4
View all reports →Affected Software
CodeIgniter4
Vulnerable Versions:
< 4.4.7
Timeline
Official Publish:
March 29th, 2024
Last Modified:
August 21st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H