CVE-2024-28871: Excessive CPU used on malformed traffic
Published Apr 4, 2024
·Updated
LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malformed request traffic, leading to excessive CPU usage. Version 0.5.47 contains a patch for the issue. No known workarounds are available.
Affected Software
2 affected components
LibHTP LibHTP<0.5.47
OISF LibHTP=0.5.46
Remediation
Event History
Apr 4, 2024
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28871?
CVE-2024-28871 has a moderate severity as it can lead to excessive CPU usage due to malformed request traffic.
2
How do I fix CVE-2024-28871?
To resolve CVE-2024-28871, upgrade LibHTP to version 0.5.47 or later.
3
What versions of LibHTP are affected by CVE-2024-28871?
LibHTP versions prior to 0.5.47 are affected by CVE-2024-28871.
4
Are there any workarounds for CVE-2024-28871?
No known workarounds are available for CVE-2024-28871.
5
What type of vulnerability is CVE-2024-28871?
CVE-2024-28871 is a denial of service vulnerability due to excessive CPU consumption.