CVE-2024-2653

EUVD-2024-1280
amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
amphphttp-client
v4.0.0-rc10 ≤
𝑥
≤ 4.0.0
ADP
amphphttp
2.0.0-beta1 ≤
𝑥
≤ 2.1.0
ADP
amphphttp
v1.6.0-rc1 ≤
𝑥
≤ 1.7.2
ADP