CVE-2024-45797

HIGH

libhtp < 0.5.49 - Denial of Service via Unbounded HTTP Header Processing

Title source: llm
STIX 2.1

Description

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and response headers can lead to excessive CPU time and memory utilization, possibly leading to extreme slowdowns. This issue is addressed in 0.5.49.

References (3)

Core 3
Core References
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://github.com/OISF/libhtp/security/advisories/GHSA-rqqp-24ch-248f
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://redmine.openinfosecfoundation.org/issues/7191

Scores

CVSS v3 7.5
EPSS 0.0070
EPSS Percentile 48.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (1)
oisf/libhtp < 0.5.49
Published Oct 16, 2024
Tracked Since Feb 18, 2026