← back
CVE-2024-23837highCWE-770

LibHTP unbounded folded header handling leads to denial service

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.2%
exploitation probability
1.2%top 35% of all CVEs
observed exploitation
nono source reports it
In short

LibHTP, an HTTP parser library, can be overwhelmed by specially crafted HTTP headers that fold (wrap) in unusual ways, causing it to spend excessive time processing them and making the service unavailable to legitimate users.

Technical detail

LibHTP contains an unbounded processing vulnerability in folded header handling (CWE-770) where maliciously crafted HTTP headers with excessive folding can trigger algorithmic complexity attacks. The vulnerability allows remote attackers to cause denial of service through network-based HTTP traffic without authentication, fixed in version 0.5.46.

Summary generated and translated by AI from the official description.
LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
OISF · libhtp