CVE-2024-28871
Excessive CPU used on malformed traffic
In short
LibHTP version 0.5.46 can consume excessive CPU when processing malformed HTTP requests, potentially causing the application to slow down or become unresponsive. This is a denial of service vulnerability that affects HTTP traffic parsing.
Technical detail
LibHTP 0.5.46 is vulnerable to a denial of service attack via malformed HTTP request traffic that triggers inefficient parsing logic, consuming excessive CPU resources. The vulnerability requires sending specially crafted HTTP requests to an affected system; the impact is resource exhaustion leading to service degradation or unavailability. Patched in version 0.5.47.
Summary generated and translated by AI from the official description.
LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malformed request traffic, leading to excessive CPU usage. Version 0.5.47 contains a patch for the issue. No known workarounds are available.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
OISF · libhtpWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →