← back
CVE-2023-34188CWE-1284

CVE-2023-34188

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.0%
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
Affected products
n/a · n/a