CVE-2024-27316
HIGH 7.5EPSS 91.3%
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS
- 91.33% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2024-04-04
- Updated
- 2025-11-04
Proof-of-concept exploits (4)
- aeyesec/CVE-2024-27316_poc2★ · 2024-04-17
- lockness-Ko/CVE-2024-27316
- SHIYUE2/2026-49975libraryattackmod
- burjoy/Apache-2.4.58-Proof-of-Concept