CVE-2019-5645

HIGH

Rapid7 Metasploit < 5.0.27 - Denial of Service via HTTP Handler Regular Expression Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-5645. PoCs published by Jose Garduno, Dreamlab Technologies AG, Angelo Seiler, Dreamlab Technologies AG, including Metasploit module auxiliary/dos/http/metasploit_httphandler_dos.

AI-analyzed exploit summary This Metasploit module exploits a DoS vulnerability in the Metasploit HTTP(S) handler by sending crafted HTTP requests that trigger ReDoS (Regular Expression Denial of Service) conditions. It supports three DoS types (GENTLE, SOFT, HARD) and tests service unresponsiveness.

Description

By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can either prevent new HTTP handler sessions from being established, or cause a resource exhaustion on the Metasploit server.

Exploits (1)

metasploit WORKING POC
by Jose Garduno, Dreamlab Technologies AG, Angelo Seiler, Dreamlab Technologies AG · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/metasploit_httphandler_dos.rb

This Metasploit module exploits a DoS vulnerability in the Metasploit HTTP(S) handler by sending crafted HTTP requests that trigger ReDoS (Regular Expression Denial of Service) conditions. It supports three DoS types (GENTLE, SOFT, HARD) and tests service unresponsiveness.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Metasploit Framework 5.0.20
No auth needed
Prerequisites: Network access to the Metasploit HTTP(S) handler
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/rapid7/metasploit-framework/pull/12433

Scores

CVSS v3 7.5
EPSS 0.8788
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (1)
rapid7/metasploit < 5.0.27
Published Sep 01, 2020
Tracked Since Feb 18, 2026