CVE Published: 04/04/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache HTTP Server Status : PUBLISHED
CVE-2024-27316 Description
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.