amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Amphp
Amphp http Amphp http-client |
|
CPEs | cpe:2.3:a:amphp:http-client:*:*:*:*:*:*:*:* cpe:2.3:a:amphp:http:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Amphp
Amphp http Amphp http-client |
|
Metrics |
ssvc
|
Fri, 06 Sep 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|

Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-02-13T17:41:15.178Z
Reserved: 2024-03-19T15:20:53.090Z
Link: CVE-2024-2653

Updated: 2024-08-01T19:18:48.205Z

Status : Awaiting Analysis
Published: 2024-04-03T18:15:07.317
Modified: 2024-11-21T09:10:13.160
Link: CVE-2024-2653
