Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-2405

CVE-2024-27316 HTTP-2: httpd: CONTINUATION frames DoS

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 2.3.14.Final, 2.2.33.Final
    • None
    • None
    • None

      There are insufficient limitations placed on the amount of CONTINUATION frames that can be sent within a single stream. This issue could allow an unauthenticated remote attacker to send packets to vulnerable servers, which could use up memory resources to cause a Denial of Service.
      We have a max header config in Undertow that cna be used to limit the amount of continuatoin frames, but it is not being enforced by default.

            flaviarnn Flavia Rainone
            flaviarnn Flavia Rainone
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: