CVE-2024-45797
HIGHlibhtp < 0.5.49 - Denial of Service via Unbounded HTTP Header Processing
Title source: llmDescription
LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory utilization, possibly leading to extreme slowdowns. This issue is addressed in 0.5.49.
References (3)
Core 3
Core References
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://redmine.openinfosecfoundation.org/issues/7191
Scores
CVSS v3
7.5
EPSS
0.0070
EPSS Percentile
48.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (1)
oisf/libhtp
< 0.5.49
Published
Oct 16, 2024
Tracked Since
Feb 18, 2026