CVE-2024-27316

Updated: 2025-11-10 01:02:02.82713

Description:

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Ubuntu 18.04 ELS apache2 2.4.29 7.5 HIGH Released CLSA-2024:1728479129 2024-10-09 11:07:36
Total: 11