First published: Thu Apr 04 2024(Updated: )
LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malformed request traffic, leading to excessive CPU usage. Version 0.5.47 contains a patch for the issue. No known workarounds are available.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
LibHTP | <0.5.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28871 has a moderate severity as it can lead to excessive CPU usage due to malformed request traffic.
To resolve CVE-2024-28871, upgrade LibHTP to version 0.5.47 or later.
LibHTP versions prior to 0.5.47 are affected by CVE-2024-28871.
No known workarounds are available for CVE-2024-28871.
CVE-2024-28871 is a denial of service vulnerability due to excessive CPU consumption.