CVE-2024-2653

Publication date

2024-04-03 17:18:29

Family

certcc

State

PUBLISHED

Description

amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.