VYPR
Unrated severityNVD Advisory· Published Apr 4, 2024· Updated Nov 4, 2025

Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames

CVE-2024-27316

Description

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

Affected products

51

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.