Description
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Exploits (2)
References (10)
Scores
CVSS v3
7.5
EPSS
0.8941
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Lab Environment
Details
CWE
CWE-770
Status
published
Products (5)
apache/http_server
2.4.17 - 2.4.59
fedoraproject/fedora
38
fedoraproject/fedora
39
fedoraproject/fedora
40
netapp/ontap
9
Published
Apr 04, 2024
Tracked Since
Feb 18, 2026