CVE-2024-51502 - CVE House
Back to Database
Status published Medium CVE-2024-51502

Panic Vulnerability in loona-hpack

Vulnerability Description

loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. This issue has been addressed in release version 0.4.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-51502

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

loona
Vulnerable Versions:
< 0.4.3

Timeline

Official Publish: November 4th, 2024
Last Modified: November 21st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)