VYPR
High severity8.2NVD Advisory· Published Apr 3, 2024· Updated Jun 17, 2026

CVE-2024-2653

CVE-2024-2653

Description

amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
amphp/httpPackagist
>= 2.0.0, < 2.1.12.1.1
amphp/httpPackagist
< 1.7.31.7.3
amphp/http-clientPackagist
>= 4.0.0-rc10, <= 4.0.0

Affected products

2

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.