HTTP/2 incoming headers exceeding the limit are...
High severity
Unreviewed
Published
Apr 4, 2024
to the GitHub Advisory Database
•
Updated Jul 30, 2024
Description
Published by the National Vulnerability Database
Apr 4, 2024
Published to the GitHub Advisory Database
Apr 4, 2024
Last updated
Jul 30, 2024
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
References