CVE-2024-2653
EUVD-2024-128003.04.2024, 18:15
amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| amphp | http-client | v4.0.0-rc10 ≤ 𝑥 ≤ 4.0.0 | ADP |
| amphp | http | 2.0.0-beta1 ≤ 𝑥 ≤ 2.1.0 | ADP |
| amphp | http | v1.6.0-rc1 ≤ 𝑥 ≤ 1.7.2 | ADP |
References