CVE-2024-27316
04.04.2024, 20:15
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.Enginsight
Vendor | Product | Version |
---|---|---|
apache | http_server | 2.4.58 ≤ 𝑥 ≤ 2.4.58 |
apache | http_server | 2.4.17 ≤ 𝑥 < 2.4.59 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
apache2 |
|
References